# ebcidn.co — SUSPICIOUS > Beware! ebcidn.co is a crypto drainer impersonating login portals. VirusTotal shows 0/95 detections. Verify on PhishDestroy before entering credentials. ## Summary PhishDestroy identifies ebcidn.co as a high-risk fake login page designed to harvest cryptocurrency wallet credentials. This domain masquerades as a legitimate service to trick users into surrendering sensitive private keys, with a payload that drains connected wallets upon login. The site’s infrastructure is engineered for deception: it leverages Google Trust Services for an SSL certificate (casting doubt on security indicators), operates on an IP address (172.67.144.168) linked to known malicious hosting, and registered through GoDaddy only months ago on October 31, 2025—indicating a recent, rapidly deployed threat. This domain has not yet been flagged by mainstream security tools, with VirusTotal currently showing 0 detections out of 95 scanners, leaving it dangerously under the radar. Its recent creation date and clean scan history make it particularly hazardous for unsuspecting users, especially those interacting with crypto platforms. The domain’s infrastructure and operational timeline suggest it is part of a growing trend of short-lived phishing domains designed to evade detection while targeting high-value victims. If you visited ebcidn.co, assume your credentials or wallet access were compromised. Immediately revoke any permissions granted to the site, transfer remaining funds to a secure wallet, and perform a full security sweep on devices used for crypto transactions. Report the domain to PhishDestroy and your wallet provider to aid in blocking further attacks. Avoid interacting with this site entirely—its clean scan status does not reflect its true malicious intent. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2025-10-31 15:00:48 - Registrar: GoDaddy.com, LLC - IP: 172.67.144.168 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/bc30cd8d-e78e-49fe-aa83-9e73dfc4af92 - PhishDestroy: https://phishdestroy.io/domain/ebcidn.co/ - LLM endpoint: https://phishdestroy.io/domain/ebcidn.co/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/ebcidn.co/ Last updated: 2026-03-26