VirusTotal
5 / 89
“Focusel | Minimalist Desktop App for Deep Work & Focus”
On August 04, 2026, the domain www.focusel.space is flagged as a potential phishing site.
The detailed PhishDestroy AI analysis below remains in English to preserve the original forensic record.
On August 04, 2026, the domain www.focusel.space is flagged as a potential phishing site. This domain was registered through HOSTINGER operations, UAB on July 06, 2026. Currently, it resolves to the IP address 66.33.60.66 and is hosted on nameservers apollo.dns-parking.com, athena.dns-parking.com, ns1.vercel-dns-3.com, and ns2.vercel-dns. The domain appears on one security blocklist, specifically PhishDestroy, indicating that it has been identified as a phishing threat by at least one security provider. Despite this, the domain is still active, which suggests ongoing malicious activity.
Analysis indicates that the domain's infrastructure and registration details are consistent with patterns often used by phishing operators. The use of HOSTINGER operations, UAB for domain registration and the choice of nameservers point to a setup that may be leveraged for quick and temporary deployment, a common tactic in phishing operations. The IP address 66.33.60.66 has not been provided with additional context such as ASN or country information, leaving these details uncertain. Defenders should be cautious and consider blocking access to www.focusel.space to prevent potential phishing attacks.
It is recommended to monitor the domain for any changes in its status or infrastructure. Additionally, organizations should educate users about the risks of phishing and how to recognize and report suspicious domains. The exact content and purpose of the phishing site have not been analyzed, so further investigation is warranted to determine the specific nature of the threat. This domain's presence on a security blocklist should be taken seriously, and proactive measures should be implemented to mitigate any potential risks.
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
Scanner note: unavailable: raw=connection_error; http=0; via=http_proxy; error=SOCKSHTTPConnectionPool(host='duplicate-disabled-377016.invalid', port=80): Max retries exceeded with url: / (Caused by
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Edge-IP reputation is not attributed to this domain.
apollo.dns-parking.comathena.dns-parking.comns1.vercel-dns-3.comns2.vercel-dns-3.comns3.vercel-dns-3.comns4.vercel-dns-3.comLocation describes the IP network.
a33f7d3a0916ac7da9e2af3e3b59e9b1932fc6bae9ad09870886e5c9290b1c2fSaved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
Google PageSpeed Insights — mobile performance audit of duplicate-disabled-377016.invalid · checked Aug 4, 2026
13 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Select your country to get official cybercrime contacts, or create a complaint draft →.
Template-based draft · optional AI wording assistance requires separate consent
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowSubmit suspicious domains to our threat database — protect the community
ReportRecent phishing reports and observed availability changes
MonitorMonitor live threats or contest this listing if you believe it's a false positive