MALICIOUS — CRITICAL
ut-partners.us - Banking Phishing Scam
ut-partners[.]
ut-partners.us masquerades as a legitimate banking site, exploiting users' trust in online financial services.
- VirusTotal
- 14/91
- Blocklists
- No stored match
- Availability
- Last known active · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@hostsailor.com.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
Evidence Analysis
ut-partners.us masquerades as a legitimate banking site, exploiting users' trust in online financial services. The domain's page title suggests a focus on mobile banking, credit cards, and loans, indicating a broad target range within the financial sector. Despite being taken down, it was flagged by 5 out of 91 vendors on VirusTotal, highlighting its malicious nature.
Registered with Sav.com LLC and hosted by Host Sailor Ltd in the Netherlands, ut-partners.us used Let's Encrypt for SSL certification. The domain was created on December 10, 2025, and PhishDestroy identified it as a threat on June 19, 2026. This timeline suggests the domain was operational for several months before detection, potentially compromising numerous users.
The domain's platform risk score of 63/100 and an abuse score of 19/100 reflect its threat level. Although it is currently offline, the presence of this domain in public blocklists, including PhishDestroy's, emphasizes the importance of proactive threat identification. Phishing domains like ut-partners.us often exploit the lag between domain registration and antivirus database updates, making early detection crucial in protecting users from financial scams.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Data coverage12 recorded checks
Threat Response Pipeline
Public Blocklist Status
VirusTotal Analysis
Evidence & External ReportsIndependent lookups and source reports
PD-20260619-C6E429 Recipient: abuse@hostsailor.com Victim safety and official reportingImmediate actions and verified reporting channels
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.