# paraguaygldev.underwriter.dev — SUSPICIOUS > paraguaygldev.underwriter.dev is linked to credential theft with 0 of 95 VirusTotal detections. Risk under investigation; avoid sharing login details. ## Summary paraguaygldev.underwriter.dev poses a credential theft risk, attempting to trick users into revealing sensitive login information. This type of threat can lead to unauthorized access to personal accounts and potential financial loss. PhishDestroy's investigation shows that this domain is currently active and has 0 detections out of 95 on VirusTotal, meaning it is not yet flagged by most scanners. The domain uses a ZeroSSL certificate and resolves to the IP address 108.61.197.174. The risk level remains under investigation due to these factors. If you have visited paraguaygldev.underwriter.dev, do not enter any personal or login information. If you have already provided credentials, change your passwords immediately and enable two-factor authentication where possible. Monitor your accounts for unusual activity and consider running a security scan on your devices. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: REGISTRAR_NOT_FOUND - IP: 108.61.197.174 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/6dc3a0a2-12da-4cb9-8009-80359f6223a0 - PhishDestroy: https://phishdestroy.io/domain/paraguaygldev.underwriter.dev/ - LLM endpoint: https://phishdestroy.io/domain/paraguaygldev.underwriter.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/paraguaygldev.underwriter.dev/ Last updated: 2026-03-26