Analysis conducted on July 31, 2026 identifies telsadminnnnnn.weebly.com as an active credential-harvesting phishing domain. The site resolves to IP address 74.115.51.8 and remains operational at the time of this report. Infrastructure analysis reveals the domain is hosted through Square, Inc. and currently lacks assigned nameservers, a configuration that may facilitate rapid takedown evasion. Detection metrics from VirusTotal indicate 14 of 91 security vendors have flagged the domain as malicious, while PhishDestroy has implemented blocking measures.
The domain appears on one security blocklist, though additional threat intelligence sources such as Google Safe Browsing and AlienVault OTX do not currently list it in provided data. No specific brand impersonation or phishing kit has been confirmed in available metadata. The exact content and target of the credential harvesting operation remain unanalyzed, as the site's page title and visual elements have not been reviewed.
Defenders should treat this domain as high-risk and implement immediate blocking at DNS, proxy, and endpoint layers. Network monitoring should prioritize connections to 74.115.51.8, particularly for credential submission patterns or unexpected authentication attempts. Given the domain's registration through a free website builder platform, security teams should also review Weebly-hosted subdomains for similar phishing activity, using the seed identifier e0e00c for correlation in internal tracking systems.