VirusTotal
5 / 89
“Fletch · Trade the dividend. Keep the stock.”
Analysis of www.fletch.finance indicates that the domain is currently active and has been associated with a generic phishing campaign.
The detailed PhishDestroy AI analysis below remains in English to preserve the original forensic record.
Analysis of www.fletch.finance indicates that the domain is currently active and has been associated with a generic phishing campaign. Network resolution shows the domain pointing to the IPv4 address 64.29.17.65. The hosting infrastructure behind this address has not been publicly attributed to a known autonomous system or country in the supplied data, limiting the ability to assess the broader threat landscape of the host. DNS queries return no identifiable nameserver records, marked as NS_NOT_FOUND, which is a common tactic to hinder forensic tracing and may indicate use of a fast‑flux or dynamically allocated DNS service.
The domain is listed on a single security blocklist and has been explicitly blocked by the PhishDestroy filtering service, confirming that at least one external mitigation platform has taken action against it. VirusTotal reports that the domain was examined by 91 scanning engines, none of which raised a detection at the time of scanning; however, the absence of vendor flags does not constitute evidence of safety, especially given the confirmed phishing classification. No SSL/TLS certificate details, HTTP response codes, page title, or brand targeting information are available, leaving the content and payload characteristics unverified.
Consequently, the primary observable indicators are the IP resolution, blocklist presence, and the PhishDestroy block. Defenders should continue to deny any network traffic to www.fletch.finance, add the domain and its IP address to local and perimeter deny lists, and monitor for any emergent activity such as new DNS records or additional blocklist listings. Ongoing vigilance is recommended, as the lack of further technical artefacts suggests the operators may be employing a minimalist infrastructure that can be rapidly redeployed or altered.
Full extracted values, their blockchain and collection source. An address found in page content does not establish who controls it.
0x3450598e419abb5609f60e4b2fda127ff0897777Format validated · Domain analysishttps://t.me/FletchFinanceStored page referenceIoC extraction recorded 2026-08-04 04:00:09 UTC
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
Scanner note: unavailable: raw=connection_error; http=0; via=http_proxy; error=SOCKSHTTPConnectionPool(host='duplicate-disabled-377202.invalid', port=80): Max retries exceeded with url: / (Caused by
Edge-IP reputation is not attributed to this domain.
Location describes the IP network.
f4c1781cd6a5a2a0e97eb3e75fb30cb5327cf1ea1202d4c1cf6f8eff3b790dceSaved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
Google PageSpeed Insights — mobile performance audit of duplicate-disabled-377202.invalid · checked Aug 4, 2026
12 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Select your country to get official cybercrime contacts, or create a complaint draft →.
Template-based draft · optional AI wording assistance requires separate consent
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowSubmit suspicious domains to our threat database — protect the community
ReportRecent phishing reports and observed availability changes
MonitorMonitor live threats or contest this listing if you believe it's a false positive