ebundletools[.]in
Resumo das evidências
Analysis of ebundletools.in confirms its use as an active credential-theft phishing domain. Registered on May 12, 2026, through Endurance International Group India Private Limited, the domain currently resolves to 188.114.97.3, an IP address geolocated to Canada and associated with CloudFlare’s network infrastructure. The domain’s nameservers—alfred.ns.cloudflare.com and imani.ns.cloudflare.com—further indicate reliance on CloudFlare’s DNS and proxy services, a common tactic to obscure the true origin of phishing infrastructure. The domain is flagged by one security vendor on VirusTotal and appears on a single security blocklist, specifically PhishDestroy. While the HTTP response currently returns a 403 status, this does not indicate inactivity; rather, it suggests the site may be selectively serving content or awaiting activation. The SSL certificate, issued by Google Trust Services (WE1), is consistent with legitimate domains but does not mitigate the domain’s malicious classification. AlienVault OTX records the domain in one threat intelligence pulse, reinforcing its association with known phishing activity. Infrastructure analysis reveals no evidence of brand impersonation or a specific phishing kit, though the domain name itself—ebundletools.in—suggests a potential focus on software or digital product scams. The lack of widespread detection across security vendors does not diminish the risk; phishing domains often evade broad detection during early deployment phases. Defenders should treat this domain as high-risk and prioritize blocking it at the DNS and network levels. Monitoring for changes in HTTP status or SSL certificate updates may provide additional indicators of evolving malicious activity.
Data Coverage
Sinais de segurança
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 12/08/2026
10 fontes externas monitoradas Sem correspondência
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo