# dubaiescortlist.com — SUSPICIOUS > PhishDestroy identifies dubaiescortlist.com as a credential theft domain with 0/95 VirusTotal detections. Domain created March 11, 2026. ## Summary PhishDestroy identifies dubaiescortlist.com as an active credential theft domain under investigation, posing an emerging threat to users expecting legitimate content. This domain exhibits multiple indicators of malicious intent. It was registered on March 11, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar with no immediate red flags but known for high-risk domain volume. The domain resolves to IP 104.21.31.89 and utilizes a Let's Encrypt SSL certificate, which provides no trust validation of the domain's legitimacy. Critically, VirusTotal currently shows 0/95 detections, suggesting this domain has evaded initial detection mechanisms. The domain has not yet been flagged on major threat intelligence feeds, but its recent creation date indicates it may be part of a newly deployed campaign. Given the credential theft threat classification, organizations and users should immediately block access to this domain at the network perimeter. Implement DNS sinkholing to redirect queries to a controlled landing page for analysis. Enable enhanced logging for any authentication attempts originating from IPs associated with this domain (104.21.31.89). User awareness campaigns should highlight the risks of entering credentials on suspicious domains, particularly those offering adult services which are commonly abused for credential harvesting. Monitor authentication logs for patterns matching this domain's SSL certificate or IP range, and consider implementing browser-based controls to block access to newly registered domains with low trust scores. Immediate action is warranted due to the domain's active status and potential for rapid campaign expansion. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-11 10:49:39 - Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED - IP: 104.21.31.89 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/319ab8ae-851d-4d3c-90ff-1dd93d223ea5 - PhishDestroy: https://phishdestroy.io/domain/dubaiescortlist.com/ - LLM endpoint: https://phishdestroy.io/domain/dubaiescortlist.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/dubaiescortlist.com/ Last updated: 2026-03-23