Перейти до звіту про безпеку
Checked 09.08.2026 Ref CED672A4

MALICIOUS — CRITICAL

etdb35y[.]com

1 of 91 security engines flagged the domain; the latest stored check returned HTTP 301.

81/100 evidence score · Critical
VirusTotal
1/91
Blocklists
No stored match
Доступність
Останній відомий активний · HTTP 301
Report / Add Evidence Appeal this listing
2026-04-28 15:10 UTCОстанній відомий активний · HTTP 301

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Цей домен було позначено як шкідливий
Системи безпеки повідомляють про виявлення: 1. Будьте дуже обережні — не вводьте облікові дані чи особисту інформацію.
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . The recorded recipient is abuse@trustname.com. The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
3 months
Reports sent
1
Latest case ID
PD-20260428-20FC17
Current status
HTTP 301 at latest stored check
Jump to section
Огляд звіту

etdb35y.com — Останній відомий активний (HTTP 301). Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 1/91 (Gridinsoft); CF Radar malicious; PhishDestroy score 81/100. Реєстратор: Fewmoretaps OU d/b/a T….

Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.

Evidence Digest

Ref CED672A4

etdb35y.com is classified critical with an evidence score of 81/100. 1 of 91 security engines flagged the domain. Registered 28 Apr 2026 via Fewmoretaps OU d/b/a Trustname.com, hosted on 188.114.97.3 (Cloudflare, Inc., CA). The latest stored check on 9 Aug 2026 returned HTTP 301 and includes a capture. 1 outgoing abuse report is recorded, most recently on 28 Apr 2026.

Stored generated summary (templated)mistral · 26.06.2026

Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.

The domain etdb35y.com has been identified as a credential theft phishing site, specifically designed to harvest financial login credentials through deceptive login portals. Analysis indicates the domain is currently offline, though it remains under active investigation due to its recent operational history and infrastructure patterns. Infrastructure analysis reveals the domain was registered on April 28, 2026, through Fewmoretaps OU d/b/a Trustname.com. It resolved to the IP address 188.114.97.3 and was flagged by one security blocklist, though it received zero detections from 95 VirusTotal vendors at the time of assessment. The domain utilized a Let's Encrypt SSL certificate, a common tactic to lend superficial legitimacy to fraudulent sites. The creation date suggests the domain was likely deployed for short-term malicious campaigns, a characteristic of credential theft operations seeking to evade detection. Current evidence indicates the domain has been taken offline, though residual risk persists due to the transient nature of such infrastructure. Organizations and users are advised to block the domain and its associated IP address (188.114.97.3) at the network level. Security teams should monitor for related domains registered through the same registrar (Fewmoretaps OU) or resolving to the same IP range, as these may indicate follow-on campaigns. End-users should be educated on recognizing credential theft tactics, particularly unsolicited login prompts mimicking financial institutions. Given the domain's recent creation and lack of prior detections, continuous monitoring of threat feeds for re-emergence is recommended.

VirusTotal
VirusTotal
1 det.
OTX references
CF Radar
Шкідливий
URLScan
URLScan
Сертифікат TLS
Let's Encrypt
Вік
3 mo
Зафіксований статус
Останній відомий активний 301
PhishDestroy
DestroyList
У списку
Reports Sent
1
Обсяг даних12 recorded checks
VirusTotal 1 / 91 URLQuery checked — no detections recorded PhishStats не перевірено OTX 23 community references CF Radar provider verdict: malicious URLScan capture збережений звіт URLScan verdict Аналіз завершено Блокування DNS не перевірено TLS valid certificate, 74d WHOIS 3 mo old Знімок екрана 2 captures · 2 sources Ланцюжок перенаправлень не досліджено
Розвіддані з мережевої безпеки Registrar context
CF Cloudflare Radar Verdict Шкідливий
Dga domains
Registrar context Trustname
Stored registration data identifies Trustname / Fewmoretaps OÜ (IANA 4318) as the registrar. PhishDestroy maintains a separate registrar investigation; that material is contextual and is not an independent detection for this domain.
Trustname Investigation

Процес реагування на загрози Pipeline

Відкриття
Checks
Reports
Доступність
14/15

Статус у публічних блоклистах

Збережений знімок

Заголовок сторінки
etdb35y.com | 522: Connection timed out
Сертифікат TLS
Valid transport encryption · Виданий Let's Encrypt · valid for 74 days

Аналітика доменів

Домен
URLScan Verdict Аналіз завершено score 0 report ↗
Сервер / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden Репутація Edge-IP не пов’язана з цим доменом.
Реєстратор Fewmoretaps OU d/b/a T… BY(BY) PhishDestroy Investigation
IP-адреса 188.114.97.3 CDN
ГеолокаціяCA Toronto, CA
МережаAS13335 · CloudFlare, Inc.
Зворотний пошук IPviewdns.info → rapiddns.io →
Початкова IP-адреса прихована за проксі CDN. Результати зворотного IP для крайової адреси містять непов’язаних орендарів; для пошуку джерела потрібен пасивний DNS або дані прозорості сертифіката.
РеєстраціяСтворено 28.04.2026 (102d)
Статус HTTP301 Moved Permanently
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Вперше виявлено28.04.2026
IoC Extractionscanned 29.07.20260 wallet · 0 Telegram IoCs
Сервери іменluciana.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 11.06.2026scanned 09.07.2026
Case ID
ICANN OVERSIGHT

Акредитація та контекст RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Нічого не надсилається автоматично.
Технології · 2 identified
Cloudflare
CDN

Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.

www.cloudflare.com 100% впевненості
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org 100% впевненості
Detected via Cloudflare Radar · Wappalyzer engine
Поскаржитися на цей домен Надішліть докази та допоможіть захистити інших

Аналіз VirusTotal

1 / 91 постачальників безпеки позначили цей домен
View on VT
Last analyzed
Gridinsoft
Докази та зовнішні звітиIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.

Європол
Знайдіть офіційний канал звітності для вашої країни ЄС
National police directory
Остерігайтеся шахраїв, які обіцяють повернути втрачені кошти! Злочинці можуть знову зв’язатися з жертвами, видаючи себе за слідчих, адвокатів або агентів із відновлення. Не сплачуйте авансових зборів і не діліться обліковими даними. Дізнайтеся більше про шахрайство у сфері відшкодування збитків →

Зверніться до місцевих органів влади

Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.

Довідник 97 країн
Чернетка за допомогою штучного інтелекту — деталі інциденту обробляються постачальником штучного інтелекту Перегляньте та подайте його самостійно
Вбудувати цей звітRead-only HTML widget
HTML · IFRAME

Вбудувати цей звіт

Поділіться цією інформацією про загрози на своєму веб-сайті або в блозі

embed.html
<iframe
  src="https://phishdestroy.io/uk/embed/domain/etdb35y.com"
  title="PhishDestroy threat report for etdb35y.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Дуже щирий лист-подяка

Генератор сатиричних чернеток

Одержувач
Контекст зборів

Це сатирична чернетка. Суми зборів є оцінками; ми не стверджуємо, що вони точно стосуються цього домену.