Skip to security report
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 4. Exercise extreme caution — do not enter credentials or personal information.
Domain security and threat intelligence

arecs[.]online

“Arecs Research Institute”

Threat verdict Critical 71/100 evidence score
Availability Content unavailable Content was unavailable in the latest observation
VirusTotal detections: 4/91
Sep 17, 2025

Evidence Summary

CRITICAL
Evidence score
71/100

This domain, arecs.online, is flagged as a phishing site impersonating the Arecs Research Institute, a fabricated entity likely designed to lend credibility to fraudulent activities. Analysis indicates the threat type is brand impersonation, targeting victims through a deceptive institutional facade rather than direct credential harvesting or cryptocurrency drainer tactics. The site employed a WordPress-based infrastructure, leveraging technologies such as MySQL, PHP, LiteSpeed, and jQuery to mimic legitimate research portals, though no specific phishing kit or payload was identified in initial scans.

Technical indicators confirm elevated risk levels: the domain resolves to IP address 82.29.189.219 and was registered on June 16, 2025, through HOSTINGER operations, UAB. VirusTotal detects the domain as malicious by 4 out of 95 security vendors, while Gridinsoft assigns a trust score of 0/100. Scamadviser rates it at 49/100, and the domain appears on one security blocklist. The SSL certificate is issued by Let’s Encrypt, a common choice for both legitimate and malicious sites due to its accessibility. Google Safe Browsing (GSB) status is not explicitly listed, but the domain’s inclusion in PhishDestroy’s blocklist further corroborates its fraudulent nature.

As of the latest assessment, arecs.online has been taken offline, likely in response to detection by security vendors and blocklist providers. However, residual risk persists due to the domain’s recent registration and the potential for infrastructure reuse. Organizations and individuals are advised to monitor for re-emergence under similar naming conventions or shared hosting infrastructure. Network defenders should update blocklists to include the domain and its associated IP, while users should verify the legitimacy of any unsolicited communications referencing research institutes or academic entities. No direct financial or credential theft was confirmed, but the impersonation tactic suggests potential for follow-on social engineering attacks.

VirusTotal
VirusTotal
4 det.
DNS Security
3/14
TLS Certificate
Let's Encrypt
Age
1.2 yr
Observed status
Content unavailable HTTP 502
PhishDestroy
DestroyList
Listed

Data Coverage

VirusTotal 4 / 91 URLQuery not checked PhishStats not checked OTX no community references CF Radar scan completed URLScan capture stored report URLScan verdict Analysis completed DNS blocks 3/14 TLS valid certificate, 30d WHOIS 14 mo old Screenshot external capture Redirect chain not probed
Security Signals
SA Scamadviser Warnings
The owner of the website is using a service to hide their identity on WHOIS According to Tranco this site has a low rank This website is (very) young.
The SSL certificate is valid This website is safe according to DNSFilter
Network Security Intelligence
DNS Provider Blocks 3 / 14
Controld Adblock Controld Family Controld Malware

Threat Response Pipeline

Discovery
Checks
Reports
Availability
12/13

Blocklist coverage

10 monitored external feeds · stored snapshot Aug 11, 2026

10 monitored external feeds No match

Detection timeline

  1. VirusTotal

    0 → 4

Community reports

Reported by 1 community member, first seen Sep 17, 2025

Stored reports
1
Unique reported URLs
1
Accepted1

Domain Intelligence

Domain
URLScan Verdict Analysis completed score 0 report ↗
Server / ASN AS47583 Hostinger International Limited
IP Reputation IP abuse confidence 0/100 0 reports checked Jul 28, 2026
Registrar Hostinger LT(LT)
IP Address 82.29.189.219 GB
GeoGB Manchester, GB
NetworkAS47583 · Hostinger International Limited
RegistrationCreated Jun 16, 2025 Expires Jun 16, 2026
HTTP Status502 Error
Time to First Unavailability 180 days
What we count Elapsed time from the first stored abuse report to the first observation that the content was unavailable. This does not establish the cause.
What each report contains Stored outgoing-report records may reference evidence available at the time, such as vendor verdicts, registration data, hosting details, classifications, or screenshots. This page does not infer the exact payload delivered, receipt, acknowledgement, or action by a recipient.
Technical detailsDNS, TLS names and timestamps
First DetectedSep 17, 2025
DOM Analysisanalyzed Mar 11, 2026DOM analysis score 71/100
Submitted URLhttp://arecs.online/
Nameserversns1.dns-parking.comns2.dns-parking.com
TLS fingerprint
TLS observationvalid from Feb 27, 2026scanned Mar 15, 2026
TLS subject alternative nameswww.arecs.online
Page Title
Arecs Research Institute
TLS Certificate
Valid transport encryption · Issued by Let's Encrypt · valid for 30 days
ICANN OVERSIGHT

Accreditation and RAA context

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Nothing is sent automatically.
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

4 / 91 security vendors flagged this domain
View on VT
Last analyzed First positive detection Previous stored snapshot: 0 detections
alphaMountain.ai
CRDF
Gridinsoft
SOCRadar
Site Performance Analysis

Google PageSpeed Insights — mobile performance audit of arecs.online · checked Jun 27, 2026

70
Needs Work
Performance
FCP
2.72s
First Contentful Paint
LCP
24.62s
Largest Contentful Paint
CLS
0.01
Cumulative Layout Shift
TBT
98ms
Total Blocking Time
SI
2.72s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

Were You Affected by This Site?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself

Check Any Domain

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

Scan Now

Report Phishing

Submit suspicious domains to our threat database — protect the community

Report

Live Threat Feed

Recent phishing reports and observed availability changes

Monitor

Stay Informed, Stay Safe

Monitor live threats or contest this listing if you believe it's a false positive

Live Threat Feed Appeal This Listing

External tools

ScamAdviserScamAdviser Trust score 49/100Status: Caution RecommendedOpen source
HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/arecs.online"
  title="PhishDestroy threat report for arecs.online"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

A Very Sincere Thank-You Note

Satirical draft generator

Recipient
Fee context

Satirical draft. Fee figures are estimates; exact attribution to this domain is not claimed.