servicodtrn-es[.]online
“Serviços DETRAN-ES VeÃculos”
PhishDestroy identifies servicodtrn-es.online as an active crypto drainer domain impersonating ServiceDTRN. This domain was flagged as a generic phishing campaign targeting cryptocurrency users through deceptive ServiceDTRN branding. The threat involves a crypto drainer kit designed to siphon funds from unsuspecting victims by mimicking legitimate ServiceDTRN interfaces or transaction prompts. No known drainer kit signatures were detected in public sandboxes at the time of analysis, suggesting a newly deployed or obfuscated payload. This domain resolves to IP 172.67.221.154 and was registered through GoDaddy.com, LLC on April 24, 2026. VirusTotal currently reports 0/95 detections, indicating low signature coverage. The SSL certificate is issued by Let's Encrypt, which is commonly exploited in phishing campaigns due to its automated issuance process. As of this report, this domain has not been blocklisted by major threat intelligence platforms, including Google Safe Browsing (GSB status: unclassified). The combination of a newly registered domain, low detection rates, and the use of a trusted SSL issuer highlights elevated risk potential. Current status is active with no confirmed takedown actions. PhishDestroy advises immediate verification of URLs and avoidance of any interactions with servicodtrn-es.online. Users should cross-reference domains against PhishDestroy’s threat database and report suspicious activity. Remaining risk is high due to undetected status on major platforms and the domain’s recent registration. Proactive monitoring and network-level blocking are recommended to mitigate exposure.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 6 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% confidenceGoogle Analytics is a free web analytics service that tracks and reports website traffic.
google.com 100% confidenceCloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% confidenceCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of servicodtrn-es.online · checked Apr 24, 2026
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive