spotify[.]portalsub[.]com
Domain Security & Threat Intelligence Report
13/95 VT
Taken Down
Dec 30, 2025
1 Blocklist
67
Threat
PhishDestroy AI
HIGH
The domain spotify.portalsub.com posed as a legitimate Spotify portal and was flagged by 13 out of 95 VirusTotal detections, indicating a high level of risk. Gridinsoft rates this domain with a trust score of 1, categorizing it as suspicious and linking it to various phishing activities. Such impersonation can lead to credential theft from unsuspecting users who may have interacted with this fraudulent site.
This deceptive domain was registered through Global Domain Group Inc and had been active for 221 days. The associated IP address is 158.94.209.90. Gridinsoft reported several red flags, including hosting concerns and being blacklisted by security providers, which underscores its malicious purpose. The domain's young age and active phishing indicators make it a noteworthy risk to potential victims.
PhishDestroy has taken proactive measures by reporting this phishing domain and has successfully taken it down. It is currently marked as dead, and ongoing monitoring is in place to prevent any resurgence of similar threats. The blocklist count stands at 1, reflecting its identification in security monitoring databases.
This deceptive domain was registered through Global Domain Group Inc and had been active for 221 days. The associated IP address is 158.94.209.90. Gridinsoft reported several red flags, including hosting concerns and being blacklisted by security providers, which underscores its malicious purpose. The domain's young age and active phishing indicators make it a noteworthy risk to potential victims.
PhishDestroy has taken proactive measures by reporting this phishing domain and has successfully taken it down. It is currently marked as dead, and ongoing monitoring is in place to prevent any resurgence of similar threats. The blocklist count stands at 1, reflecting its identification in security monitoring databases.
VirusTotal
13 Detections
URLScan.io
Gridinsoft
1/100 View ↗
Domain Age
223 days New
Site Status
Taken Down HTTP 403
DestroyList
Listed
User Reports
1 report
Security Signals
Threat Response Pipeline
Discovery
Submission
Legal
Takedown
13/14
Pre-emptive Discovery & Ingestion
Global Ecosystem Submission
Legal Notifications & Reporting
Public Transparency & Takedown
Public Blocklist Status
Evidence Capture
Domain Intelligence
Domainspotify.portalsub.com
RegistrarGlobal Domain Group Inc (USA)
IP Address158.94.209.90
CreatedJul 18, 2025 (223 days — New)
ExpiresJul 18, 2026
Nameserversns1.69host.cc
ns2.69host.cc
ns2.69host.cc
Abuse Contactsabuse@globaldomaingroup.com
abuse@lanedo.net
abuse@lanedo.net
First DetectedDec 30, 2025
Registrar Response0h
HTTP Status403
Report This Domain
Submit evidence & help protect others
VirusTotal Analysis
13 / 95 security vendors flagged this domain
View on VT
ADMINUSLabs
Criminal IP
alphaMountain.ai
BitDefender
CyRadar
ESET
Forcepoint ThreatSeeker
Fortinet
G-Data
Lionic
MalwareURL
SOCRadar
VIPRE
Evidence & External Reports
Were You Affected by This Site?
You are not alone and there is nothing to be ashamed of. Scammers are sophisticated criminals who exploit trust. Reporting your experience is the most powerful weapon against fraud — your report can prevent others from becoming victims and help law enforcement take action. Silence is the scammer's greatest advantage. Break it.
If you have interacted with this domain, entered personal information, or connected a cryptocurrency wallet — take immediate action. Below are resources to help you report the incident and protect yourself.
Chainabuse
Report crypto wallet address, transaction, or phishing URL
FBI IC3
Report internet crime (US)
Europol
Report cybercrime (EU)
Action Fraud
Report fraud & cyber crime (UK)
SEAL-ISAC
Security Alliance — crypto threat intelligence
Domain Appeal
Contest this listing if false positive
Beware of recovery scammers! After being scammed, criminals may contact you again pretending to be "recovery agents," lawyers, or investigators who claim they can retrieve your lost funds — for a fee. This is a second scam. No legitimate service will ask for upfront payment to recover stolen crypto. Learn more about recovery fraud →
Report to Your Local Authorities
Select your country to see local cybercrime reporting contacts and complaint templates.
Select your country...
Related Domain Reports
Other Domains on 158.94.209.90
More Domains at Global Domain Group Inc
Stay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive
URLScan Report