# adavaultpool.net — SUSPICIOUS > adavaultpool.net is distributing fraudulent ad network phishing scams. 0 of 95 VirusTotal vendors flagged this domain. Check the full report. ## Summary PhishDestroy identifies active phishing infrastructure linked to adavaultpool.net, a domain impersonating legitimate advertisement network services to harvest user credentials and payment data. This threat is currently categorized as a generic phishing campaign with active distribution vectors, posing significant risk to unwary users and organizations engaging with online advertising platforms. The domain adavaultpool.net was registered on February 22, 2024, through NICENIC INTERNATIONAL GROUP CO., LIMITED, resolving to IP address 104.21.62.186 and secured with a Google Trust Services SSL certificate. As of the latest assessment, this domain remains undetected by security vendors, with 0 out of 95 VirusTotal detections recorded. The absence of current blocklist entries and low detection rates suggest a potentially emerging threat vector requiring immediate attention. Current status indicates that adavaultpool.net is actively propagating fraudulent content via malvertising and phishing landing pages designed to mimic legitimate advertisement networks. Given the domain’s recent registration, clean reputation score, and deployment of valid SSL certificates, it demonstrates sophisticated operational tradecraft aimed at evading detection. Security teams and end-users are strongly advised to block network traffic to 104.21.62.186, inspect DNS resolutions for adavaultpool.net, and validate all advertisement-related domains against known threat intelligence feeds. Immediate remediation is critical to prevent credential theft, financial fraud, or downstream compromise within organizational networks. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2024-02-22 17:47:25 - Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED - IP: 104.21.62.186 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/domains/adavaultpool.net - PhishDestroy: https://phishdestroy.io/domain/adavaultpool.net/ - LLM endpoint: https://phishdestroy.io/domain/adavaultpool.net/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/adavaultpool.net/ Last updated: 2026-04-06