Skip to security report
Checked Aug 9, 2026 Ref 7DBE29D4

MALICIOUS — CRITICAL

ut-partners.us - Banking Phishing Scam

ut-partners[.]us

ut-partners.us masquerades as a legitimate banking site, exploiting users' trust in online financial services.

100/100 evidence score · Critical
VirusTotal
14/91
Blocklists
No stored match
Availability
Last known active · HTTP 200
2026-06-24 08:14 UTCLast known active · HTTP 200

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 14. Exercise extreme caution — do not enter credentials or personal information.
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . The recorded recipient is abuse@hostsailor.com. The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
1 month
Reports sent
1
Latest case ID
PD-20260619-C6E429
Current status
HTTP 200 at latest stored check
Jump to section

Evidence Analysis

Ref 7DBE29D4

ut-partners.us masquerades as a legitimate banking site, exploiting users' trust in online financial services. The domain's page title suggests a focus on mobile banking, credit cards, and loans, indicating a broad target range within the financial sector. Despite being taken down, it was flagged by 5 out of 91 vendors on VirusTotal, highlighting its malicious nature.

Registered with Sav.com LLC and hosted by Host Sailor Ltd in the Netherlands, ut-partners.us used Let's Encrypt for SSL certification. The domain was created on December 10, 2025, and PhishDestroy identified it as a threat on June 19, 2026. This timeline suggests the domain was operational for several months before detection, potentially compromising numerous users.

The domain's platform risk score of 63/100 and an abuse score of 19/100 reflect its threat level. Although it is currently offline, the presence of this domain in public blocklists, including PhishDestroy's, emphasizes the importance of proactive threat identification. Phishing domains like ut-partners.us often exploit the lag between domain registration and antivirus database updates, making early detection crucial in protecting users from financial scams.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
14 det.
URLScan
URLScan
TLS Certificate
Expired or unverified -4d
Age
8 mo
Observed status
Last known active 200
PhishDestroy
DestroyList
Listed
Reports Sent
1
Data coverage12 recorded checks
VirusTotal 14 / 91 URLQuery checked — no detections recorded PhishStats not checked OTX no community references CF Radar no data URLScan capture stored report URLScan verdict Analysis completed DNS blocks not checked TLS Expired or unverified WHOIS 8 mo old Screenshot 3 captures · 3 sources Redirect chain not probed

Threat Response Pipeline

Discovery
Checks
Reports
Availability
9/10
Threat Ingested
ut-partners.us detected and queued for full analysis
Jun 19, 2026
URLScan.io Capture
Stored URLScan report with capture artifacts
Jun 24, 2026
URLScan Verdict
URLScan analysis completed; this web-capture result does not change the page threat verdict · score 0
Jul 29, 2026
VirusTotal
14/91 recorded on VirusTotal
Jul 28, 2026
Google Safe Browsing
Jun 19, 2026
Forensic Evidence Collected
Stored evidence from URLScan.io, URLQuery, stored screenshot
Jun 24, 2026
Technical Analysis Recorded
The report contains stored technology or forensic-analysis results.
Aug 9, 2026
Sent Report Recorded
Stored sent-report record for registrar Sav.com LLC, hosting provider, 1 abuse contact
abuse@hostsailor.com
Jun 19, 2026
DestroyList Published
Jun 19, 2026
Monitoring Continues
The domain remains reachable or access-restricted; future checks may update this observation.

Public Blocklist Status

Stored Capture

Domain Intelligence

Domain
URLScan Verdict Analysis completed score 0 report ↗
Server / ASN LiteSpeed · AS60117 HS Host Sailor Ltd, AE
IP Reputation abuse score 13/100 5 reports checked Jul 19, 2026
Registrar Sav.com
IP Address 194.36.191.196 NL
GeoNL Naaldwijk, NL
NetworkAS60117 · Host Sailor Ltd
RegistrationCreated Dec 10, 2025 (241d) Expires Dec 10, 2026
Elapsed Since First Report 21h
What we count Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Last known active.
What each report contains Stored outgoing-report records may reference evidence available at the time, such as vendor verdicts, registration data, hosting details, classifications, or screenshots. This page does not infer the exact payload delivered, receipt, acknowledgement, or action by a recipient.
HTTP Status200
Technical detailsDNS, SSL SANs, timestamps
First DetectedJun 19, 2026
DOM Analysisanalyzed Jun 19, 2026score 78/100
IoC Extractionscanned Jul 29, 20260 wallet · 0 Telegram IoCs
Submitted URLhttps://ut-partners.us/
Nameserversroan.ns.cloudflare.comruth.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from May 8, 2026scanned Jun 19, 2026
Favicon Hash
Case ID
Page Title
Home | Mobile Banking, Credit Cards, Mortgages, Auto Loan
TLS Certificate
Expired or unverified · Issued by Let's Encrypt / R12
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

14 / 91 security vendors flagged this domain
View on VT
Last analyzed Previous stored snapshot: 5 detections
alphaMountain.ai
BitDefender
CRDF
CyRadar
Ermes
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
Kaspersky
Lionic
Netcraft
SOCRadar
Sophos
Evidence & External ReportsIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself
Embed This ReportRead-only HTML widget
HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/ut-partners.us"
  title="PhishDestroy threat report for ut-partners.us"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>