MALICIOUS — HIGH
berglg[.]com
PhishDestroy identifies berglg.com as a credential theft domain impersonating a private browsing environment to harvest sensitive user data.
- VirusTotal
- 3/91
- Blocklists
- No stored match
- Disponibilité
- Dernier actif connu · HTTP 301
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@trustname.com.
The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
berglg.com — Dernier actif connu (HTTP 301). Type d'arnaque : Credential Phishing. Résumé des preuves: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); PhishDestroy score 69/100. Bureau d’enregistrement: Fewmoretaps OU d/b/a T….
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Evidence Analysis
PhishDestroy identifies berglg.com as a credential theft domain impersonating a private browsing environment to harvest sensitive user data. The domain leverages a deceptive page title 'about:privatebrowsing' to mimic legitimate browser interfaces, tricking users into entering credentials or cryptocurrency wallet details under false pretenses. Security researchers should treat this as a high-priority threat due to its active status and potential for financial exploitation. This domain was flagged with 0 detections out of 95 VirusTotal scans, indicating it currently evades detection by major antivirus engines. It resolves to IP address 188.114.96.3 and was registered through Fewmoretaps OU d/b/a Trustname.com on November 23, 2025. The SSL certificate issued by Google Trust Services adds superficial legitimacy, while the recent domain creation suggests a short-lived campaign targeting unsuspecting users. Users who visited berglg.com should immediately clear browser cache and cookies, review stored credentials for unauthorized access, and consider revoking any cryptocurrency wallet permissions granted to this domain. Report the domain to your antivirus provider and block 188.114.96.3 at the network level. Avoid re-entering sensitive information on this site and monitor financial accounts for suspicious transactions.
Couverture des données13 recorded checks
Signaux de sécurité
Renseignements sur la sécurité réseau Registrar context
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confiance à 100 %HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confiance à 100 %Analyse VirusTotal
Données factuelles et rapports externesIndependent lookups and source reports
PD-20260428-526D7E Recipient: abuse@trustname.com Victim safety and official reportingImmediate actions and verified reporting channels
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.