86d9ac664f32b3117fef6b80c85afdd31edd[.]net
Analysis as of July 29, 2026 shows that the domain 86d9ac664f32b3117fef6b80c85afdd31edd.net remains active and is linked to a generic phishing operation. The domain is explicitly blocked by the PhishDestroy mitigation service and appears on one publicly available security blocklist, indicating that at least one external repository has catalogued it as malicious. VirusTotal data reveal that four of ninety‑one scanning engines have flagged the domain, providing independent confirmation of malicious intent despite the majority of scanners not yet marking it. The elevated risk rating assigned to the domain derives from this combination of active status, blocklist inclusion, and vendor detections, which together suggest a non‑trivial threat to users who may encounter the URL.
Infrastructure details such as registrar information, hosting IP address, autonomous system number, country of origin, SSL certificate attributes, HTTP response codes, or Safe Browsing verdicts are not present in the current intelligence set, limiting the ability to map the underlying server infrastructure or to assess certificate legitimacy. Likewise, no page title or brand‑specific content has been disclosed, leaving the exact appearance and targeted brand of the hosted page unknown. Defenders should enforce network‑level blocking of the domain through DNS filtering, firewall rules, and proxy controls, and should ensure that endpoint protection platforms incorporate the domain into their malicious URL repositories.
Monitoring for outbound connections to the domain’s IP address, should it become known, is advisable, as is the inclusion of the domain in email security policies to quarantine or reject messages that reference it. Users should be warned that any unsolicited request directing them to this URL is likely hostile, and security awareness training should emphasize verification of URLs before entering credentials.
Network Security Intelligence
Threat Response Pipeline
Public Blocklist Status
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive