Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse-trusted.savcom@in.wixanswers.com.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
olug[.]life
“Lloyds Bank - Welcome to Internet Banking”
The domain olug.life was registered on January 06, 2026 through Sav.com, LLC and remains active as of the report date, July 17, 2026. DNS resolution points to the public IPv4 address 102.220.160.203 and the authoritative name servers are cheryl.ns.cloudflare.com and logan.ns.cloudflare.com, indicating use of a commercial DNS provider for anonymity and resilience. The registration date and current activity suggest the domain has been operational for a few months and is presently classified under the generic_phishing threat type. No additional intelligence such as page content, malware payloads, or victim reports is available, leaving the exact phishing vector and targeted brands undefined. The lack of further infrastructure details, such as associated ASN or hosting provider beyond the IP address, limits attribution but the use of Cloudflare DNS is consistent with many phishing campaigns that seek to evade takedown. Defenders should consider adding olug.life to blocklists, monitoring network traffic for connections to 102.220.160.203, and applying DNS sinkholing where feasible. Continued observation is advised to capture any future payloads, credential harvesting pages, or associated command‑and‑control activity that may emerge as the campaign evolves.
Network Security Intelligence
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 2 identified
Google Analytics is a free web analytics service that tracks and reports website traffic.
google.com 100% confidenceVirusTotal Analysis
Evidence & External Reports
PD-20260717-43352C Recipient: abuse-trusted.savcom@in.wixanswers.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive