# connect.aethir.sbs — SUSPICIOUS > Discover why connect.aethir.sbs is flagged as a low-risk phishing site. Learn its details and stay protected with PhishDestroy insights. ## Summary PhishDestroy identifies connect.aethir.sbs as an active phishing domain associated with generic phishing threats. The domain aims to deceive users with potentially malicious intent but currently exhibits a low-risk profile. The domain was registered recently on October 23, 2025, via Atak Domain registrar and resolves to the IP address 172.67.206.18. VirusTotal flags it by only one out of 95 security vendors, indicating limited but noteworthy suspicion. Currently active, connect.aethir.sbs should be monitored closely. Users are advised to avoid interacting with this domain, and security teams should consider blocking it to mitigate potential phishing risks. ## Threat Details - Verdict: SUSPICIOUS - Site status: alive (HTTP 200) - Page title: Login ## Domain Intelligence - Registered: 2025-10-23 16:44:26 - Registrar: Atak Domain - Country: TR - IP: 172.67.206.18 - Nameservers: adi.ns.cloudflare.com pranab.ns.cloudflare.com ## Detection Status - VirusTotal: 3 vendors flagged Vendors: ["Kaspersky"] - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Screenshot: https://i.ibb.co/Y7xHSs26/1359b97a1230.png - Cloudflare Radar: https://radar.cloudflare.com/scan/d767ea5b-ef2e-4d8f-b77e-bb22db920b53 - PhishDestroy: https://phishdestroy.io/domain/connect.aethir.sbs/ - LLM endpoint: https://phishdestroy.io/domain/connect.aethir.sbs/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/connect.aethir.sbs/ Last updated: 2026-03-19