easytrdmarkets.online
“Easy Trade Markets”
Evidence Summary
This domain, easytrdmarkets.online, is currently flagged as an active credential phishing site targeting financial trading platforms. Registered on May 27, 2026, through Global Domain Group LLC, the domain resolves to IP address 163.61.188.5, hosted in the United States under an MIT-associated network. The site presents a page titled 'Easy Trade Markets,' a likely imitation of legitimate trading services, and returns an HTTP 200 status, indicating an operational front-end designed to harvest user credentials or financial details. Analysis indicates that 17 out of 95 security vendors on VirusTotal have flagged this domain as malicious, while it also appears on at least one security blocklist. The domain is actively blocked by PhishDestroy, reinforcing its classification as a high-risk phishing resource. SSL certification is provided by Let's Encrypt (R13), a common tactic among threat actors to lend superficial legitimacy to fraudulent sites. Nameservers are hosted under lytehosting.com, an infrastructure provider previously associated with other malicious domains. Infrastructure review reveals the domain was created less than two months prior to detection, a common characteristic of short-lived phishing campaigns. The Gridinsoft trust score of 1 out of 100 further corroborates the domain's malicious intent. While the exact phishing kit or targeted brand remains unconfirmed, the use of a trading-themed lure suggests an attempt to exploit users seeking financial services. Defenders should treat this domain as hostile and implement immediate blocking measures at the DNS, proxy, or endpoint level. Given its active status and recent registration, monitoring for related domains or IP associations is recommended. Security teams should also inspect logs for any prior connections to 163.61.188.5 or lytehosting.com nameservers, as these may indicate compromised endpoints or ongoing exposure to this campaign.
Threat Response Pipeline
Public Blocklist Status
Evasion evidence
Cloaking confirmed: scanners and victims see different content
The page served one response to a browser-like visitor and another to a crawler or security scanner. Cloaking exists only to keep reviewers away from the real landing page.
- Stored cloaking flag
- Observed
- Cloaking type
content_divergence- Cloaking score
- 3/6
- Last cloaking scan
- Server header seen by scanner
LiteSpeed
Scanner note: alive_content: raw=ok; http=200; via=https_proxy; server=LiteSpeed
Stored Capture · 1 source
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Community intelligence
3 community reports
CategoryFAKE_PROJECT
Data submited by Intelligence for good
Community reports
Reported by 1 community member, first seen May 26, 2026
- Stored reports
- 1
- Unique reported URLs
- 1
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive