echoes-of-valor[.]com
“Echoes of Valor”
The domain echoes-of-valor.com is associated with a generic phishing operation and has a high threat score of 70/100. The site is currently down, indicating it may have been taken down following detection efforts. Despite this, no security vendors have flagged the domain as malicious on VirusTotal, which shows 0 detections out of 95. It is listed on one public blocklist, but Google Safe Browsing has not flagged it.
Registrar information is not available, suggesting potential use of privacy protection. The domain was created on 2026-02-21 and was first seen on 2026-02-26. Given its high threat score and current status, block the domain at the perimeter and monitor the associated IP, 172.67.210.185, as an indicator of compromise.
Threat Response Pipeline
Public Blocklist Status
VirusTotal Analysis
Evidence & External Reports
“I was contacted on X/Twitter by @tudorh_eth and moved to Discord, where I was sent a link to download a fake game/staff package. After executing the package on my Windows PC, my Base wallet was drained. The malware sample I uploaded is a Lumma dropper/stealer (SHA256: 13372aa943f8eb32c9a8b6f946ed6a49118edd60051321953288b1f35611aefb). The drain transactions below show the flow from my wallet to the drainer, conversion to ETH, and subsequent splits. Victim My EOA (Base / ENS): 0xmithrandir.b”
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive