PhishDestroy first observed egrcloud.com on Jul 29, 2026. Stored content metadata identifies ["adobe"] as the apparent target. The captured page title is “ownCloud”. Page analysis recorded additional brand references to Adobe. Stored page analysis classifies the content as impersonation. Current evidence score: 99/100 (critical).
Positive findings are stored from 3 sources: VirusTotal, URLQuery, and URLScan. VirusTotal recorded 13 detections among 91 engines: alphaMountain.ai, BitDefender, Cluster25, CRDF, Forcepoint ThreatSeeker, G-Data, Gridinsoft, Lionic, MalwareURL, SafeToOpen, SOCRadar, URLQuery, VIPRE on Aug 8, 2026 at 02:17 UTC. URLQuery recorded 1 threat-system alert on Jul 29, 2026 at 12:52 UTC. URLScan returned a malicious verdict with score 100; scan metadata linked the capture to Documentlure and assigned phishing as its category on Aug 1, 2026 at 03:30 UTC. Non-positive and contextual checks: The separate external-blocklist snapshot contained no matches on Aug 8, 2026 at 10:20 UTC. Google Safe Browsing returned no flag on Jul 29, 2026 at 12:49 UTC.
HTTP 302 was recorded on Aug 8, 2026 at 10:16 UTC. Registration records for the domain list Key-Systems GmbH as the registrar and Mar 1, 2018 as the creation date. At collection time, the hostname resolved to 43.250.142.55 on AS45638 (SYNERGY WHOLESALE PTY LTD). The recorded endpoint location is Beaconsfield, AU. The stored server header is LiteSpeed. DOM analysis on Jul 29, 2026 at 14:20 UTC returned 63/100. The evidence archive retains 3 visual captures from PhishDestroy, URLScan, and URLQuery. TLS metadata lists Let's Encrypt as the certificate issuer with validity through Oct 1, 2026; checked Jul 29, 2026 at 13:02 UTC.
The content indicators and 3 positive source findings support the current ["adobe"]-themed impersonation classification.