brucksbanker.org
“Brucks Banker”
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is registry@key-systems.net.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Evidence Summary
The domain brucksbanker.org was registered on March 14, 2026 through Internet Domain Service BS Corp and is currently hosted on nameservers ns5.ddoscure.com, ns6.ddoscure.com, protected3.ddoscure.com, and protected4.ddoscure.co. The domain resolves to the IPv4 address 51.222.162.110 and remains active as of the report date, July 27, 2026. A VirusTotal scan completed on the domain involved 91 independent security vendors; none reported a detection at the time of analysis. While the absence of detections may indicate that the payload has not yet been identified by those scanners, it does not constitute a guarantee of benign behavior.
The domain is listed on a single security blocklist and is actively blocked by the PhishDestroy service, suggesting that at least one reputable anti‑phishing platform has flagged the infrastructure as malicious. No additional public intelligence such as Safe Browsing alerts, OTX references, SSL certificate details, HTTP response codes, or trust‑score metrics were observed in the available data set. Consequently, the primary evidence supporting a phishing classification consists of the registrar information, the dedicated phishing‑oriented blocklist entry, and the active block by PhishDestroy.
Uncertainty remains regarding the specific content hosted on the site, the exact phishing kit employed, and any potential victim targeting. Defenders should add brucksbanker.org to internal block lists, monitor DNS queries for the associated IP address 51.222.162.110, and continue to observe the domain for any changes in detection status across sandbox and telemetry platforms. Ongoing vigilance is advised, particularly for organizations that handle banking credentials, as the domain’s naming suggests an attempt to impersonate legitimate financial services.
Forensic History & Detection Timeline
-
Domain Status Transition Jul 30, 2026 · 00:22 UTCDomain state transitioned from dead to alive.
-
Domain Status Transition Jul 27, 2026 · 12:57 UTCDomain state transitioned from alive to dead.
-
Threat First Observed Jul 27, 2026 · 05:24 UTCDomain ingestion complete. Initial state is marked as alive pointing to IP
51.222.162.110.
Threat Response Pipeline
Public Blocklist Status
Technologies · 13 identified
VirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of brucksbanker.org · checked Jul 27, 2026
Community intelligence
2 community reports
CategoryOTHER_INVESTMENT_SCAM
Evidence & External Reports
PD-20260727-171B05 Recipient: registry@key-systems.net Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive