MALICIOUS — CRITICAL
Phishing- und Sicherheitsprüfung für skuld.ai
skuld[.]
This domain, skuld.ai, is flagged as an active credential-phishing endpoint targeting users through a hosted page that returns HTTP 200 responses.
- VirusTotal
- 3/94
- Blocklists
- 1 · ScamSniffer
- Verfügbarkeit
- Letzter bekanntermaßen aktiv · HTTP 301
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
skuld.ai — Letzter bekanntermaßen aktiv (HTTP 301). Zusammenfassung der Beweislage: VirusTotal 3/94 (SOCRadar); 1 external blocklist match (ScamSniffer); PhishDestroy score 76/100. Registrar: NameCheap.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
This domain, skuld.ai, is flagged as an active credential-phishing endpoint targeting users through a hosted page that returns HTTP 200 responses. Registered on March 27, 2026, through a widely used registrar, the domain resolves to 104.198.14.52, a Google Cloud instance in the us-west1 region. Infrastructure analysis reveals the use of Let’s Encrypt SSL certificates, a common tactic among phishing operators to lend superficial legitimacy to fraudulent sites. The domain appears on two security blocklists and is recognized in one AlienVault OTX threat intelligence pulse, indicating prior detection by automated and community-driven threat feeds. Defenders should note that four out of ninety-five security vendors on a major scanning platform have flagged skuld.ai, suggesting moderate but not universal consensus on its malicious nature. The domain remains operational as of July 12, 2026, with no signs of takedown or remediation. Its nameservers point to a registrar-controlled DNS service, which may facilitate rapid redeployment if disrupted. While the specific phishing kit or targeted brand is not confirmed in available intelligence, the consistent HTTP 200 status and active hosting on cloud infrastructure align with patterns observed in credential-harvesting campaigns. Organizations are advised to treat this domain as high-risk and implement immediate blocking at the network and endpoint levels. Given its cloud-based hosting, defenders should monitor for related indicators, such as SSL certificate fingerprints or adjacent IP ranges, which may reveal additional infrastructure tied to the same threat actor. The domain’s recent registration date and lack of historical reputation further support its classification as a likely short-lived phishing resource. No legitimate use case has been identified, and continued monitoring is recommended to assess potential shifts in hosting or targeting behavior.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Datenabdeckung12 recorded checks
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
Forensische Erkenntnisse
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of skuld.ai · checked Mar 28, 2026
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.