# auth-rax.top — SUSPICIOUS > Explore if auth-rax.top is safe or a phishing threat. Learn about its details, current status, and what you should watch out for. ## Summary PhishDestroy identifies auth-rax.top as a suspicious domain linked to generic phishing activity, currently under investigation. Although it is not flagged by any security vendors, its recent creation and suspicious naming pattern raise concerns. The domain resolves to IP address 104.21.61.84 and is registered via NameSilo, LLC. Despite a clean VirusTotal scan, the domain's infrastructure and registration details suggest potential misuse for phishing purposes. auth-rax.top remains active, and users are advised to exercise caution when interacting with it. Monitoring and further analysis are recommended to determine its intent and mitigate possible risks. ## Threat Details - Verdict: SUSPICIOUS - Site status: alive (HTTP 530) - Page title: auth-rax.top/ ## Domain Intelligence - Registered: 2026-03-06 11:07:01 - Registrar: NameSilo, LLC - Country: US - IP: 104.21.61.84 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: amalia.ns.cloudflare.com emerson.ns.cloudflare.com - SSL Issuer: none ## Detection Status - VirusTotal: 3 vendors flagged Vendors: ["Fortinet", "Gridinsoft", "SOCRadar"] - Google Safe Browsing: clean - Blocklists: 3 hits Lists: ["PhishDestroy", "MetaMask", "SEAL"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019cbc8b-dc18-75cc-86ab-c19ddaeb2035.png - Cloudflare Radar: https://radar.cloudflare.com/domains/auth-rax.top - PhishDestroy: https://phishdestroy.io/domain/auth-rax.top/ - LLM endpoint: https://phishdestroy.io/domain/auth-rax.top/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/auth-rax.top/ Last updated: 2026-03-16