# theforms.vc — SUSPICIOUS > theforms.vc was identified as a phishing domain and is now offline. Learn about its risks and what to do if you encountered it. ## Summary PhishDestroy identifies theforms.vc as a medium-risk phishing site that targeted users by mimicking legitimate services to steal sensitive information. Despite being active briefly, it posed a real threat to personal and financial data. This phishing campaign worked by using deceptive pages under theforms.vc, designed to trick visitors into submitting credentials or personal details. The domain was linked to suspicious activity flagged by multiple security blocklists and some antivirus vendors. If you visited theforms.vc, immediately change any passwords you may have entered and monitor your accounts for unauthorized activity. Avoid revisiting the site, as it is currently offline but previously hosted harmful content. ## Threat Details - Verdict: SUSPICIOUS - Site status: dead (HTTP 404) - Page title: TheForms — Empowering the brave ## Domain Intelligence - Registered: 2026-03-04 15:07:01 - Registrar: NameCheap, Inc. - Country: US - IP: 188.114.96.3 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: jaxson.ns.cloudflare.com tara.ns.cloudflare.com - SSL Issuer: TRAEFIK DEFAULT CERT ## Detection Status - VirusTotal: 3 vendors flagged Vendors: ["Gridinsoft", "Seclookup", "SOCRadar"] - Google Safe Browsing: clean - Blocklists: 3 hits Lists: ["PhishDestroy", "MetaMask", "SEAL"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019cb906-4008-761e-8d24-431e715f8d52.png - Cloudflare Radar: https://radar.cloudflare.com/scan/0a930d06-d074-468b-9469-aad4ae7b1a6a - Wayback Machine: https://web.archive.org/web/https://theforms.vc - PhishDestroy: https://phishdestroy.io/domain/theforms.vc/ - LLM endpoint: https://phishdestroy.io/domain/theforms.vc/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/theforms.vc/ Last updated: 2026-03-19