# duadua0326h.rajabandot999.com — SUSPICIOUS > duadua0326h.rajabandot999.com is a live fake login page with 0/95 VirusTotal detections, stealing credentials via fraudulent forms. ## Summary PhishDestroy identifies duadua0326h.rajabandot999.com as an active credential-stealing site designed to trick users into submitting login details to harvest accounts. The domain presents a convincing fake login form that mimics a legitimate service, capturing usernames and passwords when entered. Once harvested, stolen credentials are frequently used for account takeovers, financial fraud, or sold on underground markets. This is a high-risk trap operating under the guise of a secure page, and interacting with it can lead to immediate compromise of personal or corporate accounts. This domain was flagged as a generic phishing host with zero VirusTotal detections out of 95 engines, meaning no antivirus currently recognizes it as malicious. It was registered on September 24, 2025, through NAMECHEAP INC and resolves to IP 172.67.148.248. Its SSL certificate issued by Google Trust Services adds a false sense of legitimacy, but the domain’s recent creation and clean VT score suggest it is a newly launched operation still evading detection. The registrar and hosting infrastructure are consistent with bulk disposable phishing operations, designed for quick deployment and takedown resistance. If you visited duadua0326h.rajabandot999.com, do not enter any credentials or personal information. Close the tab immediately. Change passwords for any accounts you may have mistakenly entered, especially if you reused passwords. Run a malware scan using reputable antivirus software. Report the domain to your email provider or browser security team. Block the domain at your network level or via browser extensions like uBlock Origin. Monitor financial accounts for unauthorized transactions. Stay vigilant for follow-up phishing attempts leveraging stolen credentials. Consider enabling multi-factor authentication on all critical accounts to mitigate the risk of takeover. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2025-09-24 17:02:47 - Registrar: NAMECHEAP INC - IP: 172.67.148.248 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/97ec1e05-ca2f-4eac-9111-848507d7cb82 - PhishDestroy: https://phishdestroy.io/domain/duadua0326h.rajabandot999.com/ - LLM endpoint: https://phishdestroy.io/domain/duadua0326h.rajabandot999.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/duadua0326h.rajabandot999.com/ Last updated: 2026-03-22