VirusTotal
5 / 89
“Fletch · Trade the dividend. Keep the stock.”
Analysis of www.fletch.finance indicates that the domain is currently active and has been associated with a generic phishing campaign.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Analysis of www.fletch.finance indicates that the domain is currently active and has been associated with a generic phishing campaign. Network resolution shows the domain pointing to the IPv4 address 64.29.17.65. The hosting infrastructure behind this address has not been publicly attributed to a known autonomous system or country in the supplied data, limiting the ability to assess the broader threat landscape of the host. DNS queries return no identifiable nameserver records, marked as NS_NOT_FOUND, which is a common tactic to hinder forensic tracing and may indicate use of a fast‑flux or dynamically allocated DNS service.
The domain is listed on a single security blocklist and has been explicitly blocked by the PhishDestroy filtering service, confirming that at least one external mitigation platform has taken action against it. VirusTotal reports that the domain was examined by 91 scanning engines, none of which raised a detection at the time of scanning; however, the absence of vendor flags does not constitute evidence of safety, especially given the confirmed phishing classification. No SSL/TLS certificate details, HTTP response codes, page title, or brand targeting information are available, leaving the content and payload characteristics unverified.
Consequently, the primary observable indicators are the IP resolution, blocklist presence, and the PhishDestroy block. Defenders should continue to deny any network traffic to www.fletch.finance, add the domain and its IP address to local and perimeter deny lists, and monitor for any emergent activity such as new DNS records or additional blocklist listings. Ongoing vigilance is recommended, as the lack of further technical artefacts suggests the operators may be employing a minimalist infrastructure that can be rapidly redeployed or altered.
Full extracted values, their blockchain and collection source. An address found in page content does not establish who controls it.
0x3450598e419abb5609f60e4b2fda127ff0897777Format validated · Domain analysishttps://t.me/FletchFinanceStored page referenceIoC extraction recorded 2026-08-04 04:00:09 UTC
Bu ana bilgisayar için saklanmış tarayıcı-karşı-tarayıcı gözlemleri ile Keitaro tarzı trafik dağıtım sistemleri için gerçek zamanlı parmak izi kontrolü.
Tarayıcı notu: unavailable: raw=connection_error; http=0; via=http_proxy; error=SOCKSHTTPConnectionPool(host='duplicate-disabled-377202.invalid', port=80): Max retries exceeded with url: / (Caused by
Edge-IP itibarı bu etki alanıyla ilişkilendirilmez.
Location describes the IP network.
f4c1781cd6a5a2a0e97eb3e75fb30cb5327cf1ea1202d4c1cf6f8eff3b790dceSaved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
Google PageSpeed Insights — mobile performance audit of duplicate-disabled-377202.invalid · checked Aug 4, 2026
12 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Template-based draft · optional AI wording assistance requires separate consent
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraŞüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirSon kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleCanlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin