MALICIOUS — CRITICAL
skuld[.]ai
This domain, skuld.ai, is flagged as an active credential-phishing endpoint targeting users through a hosted page that returns HTTP 200 responses.
- VirusTotal
- 3/94
- Blocklists
- 1 · ScamSniffer
- Kullanılabilirlik
- Bilinen son aktif · HTTP 301
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
skuld.ai — Bilinen son aktif (HTTP 301). Kanıt özeti: VirusTotal 3/94 (SOCRadar); 1 external blocklist match (ScamSniffer); PhishDestroy score 76/100. Kayıt kuruluşu: NameCheap.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
skuld.ai Safety Check — Credential Phishing Detected
This domain, skuld.ai, is flagged as an active credential-phishing endpoint targeting users through a hosted page that returns HTTP 200 responses.
This domain, skuld.ai, is flagged as an active credential-phishing endpoint targeting users through a hosted page that returns HTTP 200 responses. Registered on March 27, 2026, through a widely used registrar, the domain resolves to 104.198.14.52, a Google Cloud instance in the us-west1 region. Infrastructure analysis reveals the use of Let’s Encrypt SSL certificates, a common tactic among phishing operators to lend superficial legitimacy to fraudulent sites. The domain appears on two security blocklists and is recognized in one AlienVault OTX threat intelligence pulse, indicating prior detection by automated and community-driven threat feeds. Defenders should note that four out of ninety-five security vendors on a major scanning platform have flagged skuld.ai, suggesting moderate but not universal consensus on its malicious nature. The domain remains operational as of July 12, 2026, with no signs of takedown or remediation. Its nameservers point to a registrar-controlled DNS service, which may facilitate rapid redeployment if disrupted. While the specific phishing kit or targeted brand is not confirmed in available intelligence, the consistent HTTP 200 status and active hosting on cloud infrastructure align with patterns observed in credential-harvesting campaigns. Organizations are advised to treat this domain as high-risk and implement immediate blocking at the network and endpoint levels. Given its cloud-based hosting, defenders should monitor for related indicators, such as SSL certificate fingerprints or adjacent IP ranges, which may reveal additional infrastructure tied to the same threat actor. The domain’s recent registration date and lack of historical reputation further support its classification as a likely short-lived phishing resource. No legitimate use case has been identified, and continued monitoring is recommended to assess potential shifts in hosting or targeting behavior.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Veri kapsamı12 recorded checks
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
Adli İstihbarat
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of skuld.ai · checked Mar 28, 2026
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.