This domain, brauner.com.pl, is currently active and has been identified as a credential‑harvesting phishing infrastructure. Registration data shows it was created on 17 February 2007 through the Globtel Internet Szymon Hersztek registrar. The domain resolves to the IPv4 address 84.205.190.80 and is served by the authoritative name servers ns5.webd.pl and ns7.webd.pl. Multiple defensive feeds have flagged the domain: it appears on three security blocklists, including PhishDestroy, MetaMask, and SEAL, indicating that these platforms are already blocking traffic to the host.
VirusTotal analysis reports that three out of ninety‑one scanned security vendors have flagged the domain, reinforcing the suspicion of malicious use. No public evidence of SSL certificates, HTTP response codes, or Safe Browsing listings is available in the current intelligence set, so the presence of encryption or browser‑level warnings cannot be confirmed at this time. The limited data set prevents a definitive attribution of the phishing kit or the specific brand being impersonated, and the exact content served by the site has not been publicly captured.
Nonetheless, the convergence of registration age, hosting on a single IP, and inclusion on known anti‑phishing blocklists warrants a high‑risk classification. Defenders should block or monitor traffic to 84.205.190.80 and to brauner.com.pl at network perimeter devices, update intrusion detection signatures to include the domain and its name‑server pair, and consider adding it to internal threat intelligence feeds. Continuous re‑scanning with multi‑engine services is recommended to capture any future changes in the site’s payload or hosting configuration.