login-hubspot[.]com
Evidence Summary
login-hubspot.com is currently listed as an active credential‑phishing infrastructure targeting users of HubSpot services. The domain appears on a single security blocklist and has been explicitly blocked by the PhishDestroy filtering service, indicating that at least one reputable anti‑phishing feed has identified it as malicious. VirusTotal analysis shows that three of ninety‑one scanned security vendors have raised detections for the domain, providing independent corroboration of its malicious intent. No additional public data such as registrar details, IP address allocation, SSL certificate information, or HTTP response codes are presently available in the intelligence feed, leaving the underlying hosting environment and technical footprint largely uncharacterized.
The absence of a published page title or Safe Browsing verdict further limits visibility into the specific lure employed, although the classification as credential phishing suggests that the site likely presents a counterfeit login interface to harvest HubSpot credentials. Defenders should prioritize immediate containment by adding login-hubspot.com to network‑level deny lists and ensuring that endpoint protection suites incorporate the domain into their blocklists. Continuous monitoring of threat‑intelligence feeds for new detections, as well as periodic re‑scans on VirusTotal, is advised to capture any evolution in the threat actor’s tooling or hosting changes. Organizations that employ HubSpot should also reinforce user awareness training, emphasizing verification of URL authenticity before credential entry, and consider implementing multi‑factor authentication to mitigate the impact of any potential credential compromise.
The limited visibility into the domain’s registration data prevents attribution of the operator, and the lack of SSL certificate transparency logs hampers verification of potential certificate misuse.
Data Coverage
Network Security Intelligence
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 11, 2026
10 monitored external feeds No match
Detection timeline
-
Domain status
Reachable → Unreachable
-
Domain status
Unreachable → Reachable
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive