Analysis conducted on July 28, 2026 identifies solicitudenlineabcol.duckdns.org as an active high-risk phishing domain targeting financial institutions. The subdomain is registered through DuckDNS, a dynamic DNS provider frequently exploited for short-lived malicious campaigns due to its lack of upfront verification. Infrastructure analysis reveals the domain currently resolves to IP address 66.55.78.230, though no autonomous system or geolocation data is confirmed in available intelligence. Nameserver records return NS_NOT_FOUND, indicating potential misconfiguration or deliberate evasion of standard DNS resolution.
Detection metrics show the domain is flagged by 21 of 91 security vendors on VirusTotal, with specific blocking by PhishDestroy and OpenPhish. It appears on two independent security blocklists, reinforcing its classification as malicious. The domain remains operational as of the report date, with no evidence of takedown or suspension by the registrar. The exact content of the phishing site is not yet analyzed, though the subdomain name 'solicitudenlineabcol' suggests a focus on online banking requests, potentially mimicking a legitimate financial portal.
No brand name, phishing kit identifier, or HTTP response data is provided in current intelligence, limiting further attribution. Defenders are advised to treat all connections to this domain as hostile and implement immediate blocking at the DNS, network, and endpoint layers. Organizations should monitor for credential harvesting attempts linked to this infrastructure, particularly those targeting Spanish-speaking users or banking customers. Given the domain's persistent activity and dynamic DNS hosting, defenders should anticipate rapid reconfiguration or migration to alternative subdomains under DuckDNS.