MALICIOUS — CRITICAL
etdb35y[.]com
1 of 91 security engines flagged the domain; the latest stored check returned HTTP 301.
- VirusTotal
- 1/91
- Blocklists
- No stored match
- Доступність
- Останній відомий активний · HTTP 301
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@trustname.com.
The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
etdb35y.com — Останній відомий активний (HTTP 301). Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 1/91 (Gridinsoft); CF Radar malicious; PhishDestroy score 81/100. Реєстратор: Fewmoretaps OU d/b/a T….
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Digest
etdb35y.com is classified critical with an evidence score of 81/100. 1 of 91 security engines flagged the domain. Registered 28 Apr 2026 via Fewmoretaps OU d/b/a Trustname.com, hosted on 188.114.97.3 (Cloudflare, Inc., CA). The latest stored check on 9 Aug 2026 returned HTTP 301 and includes a capture. 1 outgoing abuse report is recorded, most recently on 28 Apr 2026.
Stored generated summary (templated)mistral · 26.06.2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
The domain etdb35y.com has been identified as a credential theft phishing site, specifically designed to harvest financial login credentials through deceptive login portals. Analysis indicates the domain is currently offline, though it remains under active investigation due to its recent operational history and infrastructure patterns. Infrastructure analysis reveals the domain was registered on April 28, 2026, through Fewmoretaps OU d/b/a Trustname.com. It resolved to the IP address 188.114.97.3 and was flagged by one security blocklist, though it received zero detections from 95 VirusTotal vendors at the time of assessment. The domain utilized a Let's Encrypt SSL certificate, a common tactic to lend superficial legitimacy to fraudulent sites. The creation date suggests the domain was likely deployed for short-term malicious campaigns, a characteristic of credential theft operations seeking to evade detection. Current evidence indicates the domain has been taken offline, though residual risk persists due to the transient nature of such infrastructure. Organizations and users are advised to block the domain and its associated IP address (188.114.97.3) at the network level. Security teams should monitor for related domains registered through the same registrar (Fewmoretaps OU) or resolving to the same IP range, as these may indicate follow-on campaigns. End-users should be educated on recognizing credential theft tactics, particularly unsolicited login prompts mimicking financial institutions. Given the domain's recent creation and lack of prior detections, continuous monitoring of threat feeds for re-emergence is recommended.
Обсяг даних12 recorded checks
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Докази та зовнішні звітиIndependent lookups and source reports
PD-20260428-20FC17 Recipient: abuse@trustname.com Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.