MALICIOUS — CRITICAL
teulltiyfb4xv[.]dappdata[.]cc
18 of 93 security engines flagged the domain; the latest stored check returned HTTP 502.
- VirusTotal
- 18/93
- Blocklists
- No stored match
- Verfügbarkeit
- Inhalt nicht verfügbar · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
teulltiyfb4xv.dappdata.cc — Inhalt nicht verfügbar (HTTP 502). Markenidentität: Telegram; Betrugstyp: Investment Scam. Zusammenfassung der Beweislage: VirusTotal 18/93 (ADMINUSLabs, BitDefender, CyRadar, ESET, Forcepoint ThreatSeeker); URLScan malicious verdict; Google Safe Browsing flagged; PhishDestroy score 95/100. Registrar: Gname.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Digest
teulltiyfb4xv.dappdata.cc is classified critical with an evidence score of 95/100. 18 of 93 security engines flagged the domain. Registered 21 Feb 2026 via Gname.com Pte. Ltd., hosted on 38.85.201.54 (FD-298-8796 - FASTNET DATA INC, US, US). The latest stored check on 9 Aug 2026 returned HTTP 502 and includes a capture.
Stored generated summary (templated)mistral · 25.06.2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
This domain, teulltiyfb4xv.dappdata.cc, is identified as a high-risk phishing site impersonating Telegram. Analysis indicates the page title explicitly matches the Telegram brand, suggesting an attempt to deceive users into submitting credentials or sensitive information. No drainer kit signatures were detected, but the domain’s infrastructure aligns with typical phishing campaigns targeting messaging platforms. Infrastructure analysis reveals the following technical indicators: the domain resolves to IP 38.85.201.54, hosted under AS8796 (FASTNET DATA INC) in the US. It was registered on February 21, 2026, through Gname.com Pte. Ltd., and currently holds no SSL certificate. Google Safe Browsing categorizes it as phishing, while VirusTotal reports 18/95 security vendors flagging it as malicious. The domain appears on two blocklists: PhishDestroy and PhishingDB. The domain is currently offline, reducing immediate risk to users. However, residual threats persist due to potential credential harvesting prior to takedown. Organizations should monitor for related indicators, including the IP 38.85.201.54 and registrar patterns, to prevent recurrence. Users who accessed the site should rotate credentials and verify account integrity. No further active exploitation is confirmed, but vigilance remains necessary given the domain’s recent phishing classification.
Datenabdeckung12 recorded checks
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
VirusTotal-Analyse
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.