# qwse.lowcy.live — SUSPICIOUS > qwse.lowcy.live is hosting a fraudulent login page phishing scam. This active campaign mimics legitimate login portals to steal credentials. ## Summary PhishDestroy identifies an active phishing campaign targeting unsuspecting users via the domain qwse.lowcy.live, which impersonates legitimate login interfaces to harvest credentials. This domain exhibits elevated risk factors, confirmed by 1 out of 95 VirusTotal security vendors flagging it. Resolving to IP 172.67.185.115, qwse.lowcy.live operates under a Let's Encrypt SSL certificate, a common tactic to lend false legitimacy to phishing sites. While specific creation date and blocklist status remain unverified in public sources, the domain's low detection rate suggests it is either newly deployed or carefully evading standard filters. Trust scores are further diminished by its reliance on shared hosting infrastructure, a known vector for malicious activity. To mitigate exposure, users should avoid interacting with this domain entirely and report it to their security teams or browser vendors. Organizations must implement DNS-level blocking for this domain and IP address, as well as educate employees on recognizing credential-harvesting phishing attempts. Immediate takedown requests should be submitted to hosting providers and registrars, leveraging the 1/95 VirusTotal detection as supporting evidence to accelerate the process. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: REGISTRAR_NOT_FOUND - IP: 172.67.185.115 ## Detection Status - VirusTotal: 1 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/6d46f527-d2c4-4064-ac71-5c990bd04c2d - PhishDestroy: https://phishdestroy.io/domain/qwse.lowcy.live/ - LLM endpoint: https://phishdestroy.io/domain/qwse.lowcy.live/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/qwse.lowcy.live/ Last updated: 2026-03-25