# h5.billynational.com — SUSPICIOUS > h5.billynational.com is actively hosting credential phishing targeting login details. VirusTotal flags 3/95 vendors. Check the full report. ## Summary PhishDestroy identifies h5.billynational.com as an active credential-phishing domain designed to steal login credentials through deceptive web forms. The site mimics legitimate login portals, luring victims into entering their usernames and passwords under false pretenses. Once harvested, these credentials can be exploited for account takeovers, financial fraud, or further social engineering attacks against contacts in the victim’s network. Users who encounter unsolicited links to this domain—especially in emails, messages, or pop-ups—should avoid interacting with it entirely. This domain was flagged by 3 out of 95 VirusTotal security vendors, indicating recognized malicious intent despite its recent appearance. Registered on August 9, 2025, through Name.com, Inc., it leverages a Let’s Encrypt SSL certificate to appear legitimate and resolves to IP address 118.107.25.167. Its recent creation suggests an opportunistic campaign, likely targeting users awaiting expected communications or services. The low detection rate at the time of analysis underscores how quickly threat actors deploy new infrastructure to evade initial screening. If you’ve already visited h5.billynational.com, avoid entering any personal or login information. Review account credentials used on this site immediately, enable multi-factor authentication where possible, and consider changing passwords for accounts accessed via this domain. Report the domain to your IT/security team or through your organization’s incident response channel. Monitor financial and email accounts for unusual activity, as compromised credentials may be used in follow-on attacks. If you suspect exposure, reset passwords from a known-safe device and scan for malware to prevent further unauthorized access. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2025-08-09 20:53:01 - Registrar: Name.com, Inc. - IP: 118.107.25.167 ## Detection Status - VirusTotal: 3 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/domains/h5.billynational.com - PhishDestroy: https://phishdestroy.io/domain/h5.billynational.com/ - LLM endpoint: https://phishdestroy.io/domain/h5.billynational.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/h5.billynational.com/ Last updated: 2026-04-08