The domain ww547.scotaibank.com was registered on April 11, 2002 through GoDaddy.com, LLC and currently resolves to the IPv4 address 34.160.121.137. DNS resolution is served by ns1.torresdns.com and ns2.torresdns.com, indicating that the infrastructure is hosted on a public DNS provider rather than a dedicated, hardened environment. VirusTotal records show that 15 of 91 security vendors have flagged the domain, suggesting that multiple detection engines have identified malicious characteristics associated with the host.
Independent phishing feeds, including PhishDestroy and OpenPhish, have already added the domain to their blocklists, and it appears on two additional security blocklists, reinforcing the consensus that the domain is being used for malicious purposes. The domain is classified as a banking phishing site, targeting customers of a financial institution, and is listed as active with a high risk rating. No public SSL certificate details, HTTP response codes, or page titles have been published, leaving the exact content of the site unverified.
Defenders should immediately add 34.160.121.137 to network denial lists, enforce DNS filtering for ww547.scotaibank.com, and monitor outbound traffic for connections to the identified IP address. Continuous re‑verification of the domain’s status is advised, as the lack of visible page content means that the phishing campaign could evolve or relocate while retaining the same infrastructure.