xmtfgmjannwvopbva[.]trump[.]ldc325l[.]org[.]np
“Index of /”
xmtfgmjannwvopbva.trump.ldc325l.org.np — 확인되지 않음. 증거 요약: VirusTotal 9/91 (BitDefender, Chong Lua Dao, CyRadar, Fortinet, G-Data); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 85/100.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
PhishDestroy identifies xmtfgmjannwvopbva.trump.ldc325l.org.np as a generic phishing threat. This domain was designed to deceive users into divulging sensitive information, though no specific brand impersonation or drainer kit has been confirmed. Its suspicious structure and subdomain naming pattern suggest an intent to appear legitimate while hosting fraudulent content.
Technical analysis reveals that this domain was created on April 23, 2026, and is registered through an unidentified registrar. It resolves to IP address 135.235.195.147 and uses a Let's Encrypt SSL certificate (R12) to appear secure. VirusTotal data shows 2 out of 95 security vendors flagging it as malicious, and it appears on 3 security blocklists. The page title was "Index of /", indicating a directory listing that could host phishing files. The domain is not listed on Google Safe Browsing, but its blocklist presence and low detection rate suggest it was active but not widely reported.
Currently, the domain is offline and has been taken down. This is a positive outcome, but residual risk remains as similar domains may reappear. Users should avoid interacting with any communications referencing this domain and report any phishing attempts. PhishDestroy recommends monitoring for related subdomains and maintaining updated security software to detect future threats.
위협 대응 Pipeline
공개 차단 목록 상태
도메인 인텔리전스
기술적 세부 사항DNS, SSL SAN, 타임스탬프
VirusTotal 분석
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.