# caddun.com — SUSPICIOUS > PhishDestroy identifies caddun.com as a fake login scam. Flagged by 1 of 95 VirusTotal vendors. Check the full report. ## Summary PhishDestroy identifies the domain caddun.com as an active fake login scam designed to deceive users into submitting sensitive credentials. The threat is currently classified as elevated, indicating a high likelihood of malicious intent and potential for user compromise. This domain is not a generic phishing site but specifically engineered to mimic legitimate login portals, likely targeting unsuspecting visitors with fraudulent authentication requests. This domain was flagged by 1 of 95 VirusTotal security vendors, indicating limited but present detection within the cybersecurity community. The domain is registered through Cloudflare, Inc., a privacy-focused registrar known for masking ownership details, and resolves to the IP address 104.21.43.168. While the exact creation date is not provided in available data, the IP address is associated with Cloudflare's infrastructure, which is commonly leveraged by threat actors to obfuscate malicious activities. Despite its recent detection, the domain has not yet accumulated a significant blocklist presence or trust scores, reinforcing its elevated risk profile. Given the active status and specific threat type, users are strongly advised to avoid interacting with caddun.com or any associated login prompts. The risk of credential theft or malware delivery remains high. Organizations should consider blocking the domain at the network level and updating endpoint protections to flag this domain as malicious. If exposure has occurred, users should immediately change passwords for any accounts potentially linked to this domain and enable multi-factor authentication where available. Continuous monitoring for anomalous login attempts or credential reuse is recommended to mitigate downstream risks. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 104.21.43.168 ## Detection Status - VirusTotal: 1 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - PhishDestroy: https://phishdestroy.io/domain/caddun.com/ - LLM endpoint: https://phishdestroy.io/domain/caddun.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/caddun.com/ Last updated: 2026-03-26