# waronusd1.run — SUSPICIOUS > waronusd1.run is under investigation for phishing risks. Stay cautious and avoid interacting with this domain until more info is available. ## Summary PhishDestroy identifies waronusd1.run as a domain associated with generic phishing activity. It is currently classified under investigation due to suspicious behavior patterns. The domain resolves to IP 188.114.97.3 and has no detections on VirusTotal, indicating no direct malware flags yet. However, the domain's infrastructure and activity warrant caution. Status is active with ongoing monitoring. Users are advised to avoid this domain and report suspicious communications. Further analysis is underway to determine the full scope of the threat. ## Threat Details - Verdict: SUSPICIOUS - Site status: dead (HTTP 403) - Target brand: WarOnUSD1 - Page title: Just a moment... ## Domain Intelligence - Registered: 2026-03-09 13:07:02 - IP: 188.114.97.3 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: amos.ns.cloudflare.com maya.ns.cloudflare.com - SSL Issuer: Let's Encrypt / E7 ## Detection Status - VirusTotal: 1 vendors flagged Vendors: ["SOCRadar"] - Google Safe Browsing: clean - Blocklists: 3 hits Lists: ["PhishDestroy", "MetaMask", "SEAL"] ## Evidence - Screenshot: https://i.ibb.co/LX8cDP7H/4f40ab937281.png - Cloudflare Radar: https://radar.cloudflare.com/scan/5a46c6bf-7269-498b-a73a-8cea222e4266 - PhishDestroy: https://phishdestroy.io/domain/waronusd1.run/ - LLM endpoint: https://phishdestroy.io/domain/waronusd1.run/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/waronusd1.run/ Last updated: 2026-03-19