# user.primesignalgate.com — SUSPICIOUS > user.primesignalgate.com is a credential phishing site detected on VirusTotal (0/95). Learn how this fake PrimeSignal gateway steals credentials. ## Summary PhishDestroy identifies user.primesignalgate.com as an active credential harvesting portal masquerading as a legitimate PrimeSignal gateway for high-risk users. This domain was flagged under a generic phishing classification and is currently under investigation by threat intelligence teams. The page mimics PrimeSignal’s login interface, tricking victims into submitting corporate email credentials into a counterfeit form hosted at this TLS-enabled endpoint. Evidence supporting this advisory includes VirusTotal’s 0/95 detection ratio, a domain creation date of April 08, 2026, registration via PDR Ltd. PublicDomainRegistry, and resolution to IP 172.67.159.190. The presence of a Let’s Encrypt SSL certificate underscores the domain’s deceptive legitimacy. While currently unblocked in most commercial feeds, the domain’s recent registration and zero detections suggest a newly deployed operation that may expand rapidly across enterprise environments. Users who visited this domain should immediately change any credentials entered, enable multi-factor authentication on all business-critical accounts, and scan internal systems for lateral movement artifacts. Isolate affected endpoints and report the incident to the security operations center. Monitor for phishing emails referencing “PrimeSignal” or “signal gate” services and update blocklists with this IP and domain. Avoid restoring browser sessions without clearing cached data to prevent reinfection. This site exemplifies the growing trend of short-lived domains used in targeted credential harvesting campaigns. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-04-08 14:54:50 - Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com - IP: 172.67.159.190 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/domains/user.primesignalgate.com - PhishDestroy: https://phishdestroy.io/domain/user.primesignalgate.com/ - LLM endpoint: https://phishdestroy.io/domain/user.primesignalgate.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/user.primesignalgate.com/ Last updated: 2026-04-10