# e5fd.pinit.eth.limo — MALICIOUS > e5fd.pinit.eth.limo is a confirmed Ethereum phishing domain flagged by 6 of 95 VirusTotal vendors. Avoid entering credentials or crypto wallet details to. ## Summary PhishDestroy identifies e5fd.pinit.eth.limo as an active Ethereum phishing domain currently distributing malicious content. This domain poses as a legitimate PinIt service to harvest cryptocurrency wallet credentials and private keys. Flagged by 6 of 95 VirusTotal security vendors, it resolves to IP 3.135.72.151 using a Let's Encrypt SSL certificate. The domain appears to leverage Ethereum Name Service (ENS) branding through its .eth.limo subdomain to appear authentic. PhishDestroy's analysis reveals this domain is actively engaged in credential harvesting operations targeting Ethereum users. The 6/95 detection ratio on VirusTotal indicates partial coverage by security vendors, suggesting this threat may evade some detection systems. The domain's infrastructure on AWS (IP 3.135.72.151) combined with free SSL certificates demonstrates common tactics used by phishing operators to appear legitimate while maintaining low operational costs. Users should immediately cease all interactions with this domain and verify their cryptocurrency wallet security. PhishDestroy recommends blocking IP 3.135.72.151 at firewall level and checking wallet transaction histories for unauthorized transfers. Never enter seed phrases or private keys on any website claiming to be PinIt or similar services. Report this domain to your wallet provider and consider transferring funds to a newly generated wallet address if exposure occurred. Always verify website URLs through official channels before entering sensitive information. ## Threat Details - Verdict: MALICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: REGISTRAR_NOT_FOUND - IP: 3.135.72.151 ## Detection Status - VirusTotal: 6 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/8322e2cc-5605-4250-9905-3a743038a7d2 - PhishDestroy: https://phishdestroy.io/domain/e5fd.pinit.eth.limo/ - LLM endpoint: https://phishdestroy.io/domain/e5fd.pinit.eth.limo/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/e5fd.pinit.eth.limo/ Last updated: 2026-03-22