xmtfgmjannwvopbva[.]trump[.]ldc325l[.]org[.]np
“Index of /”
xmtfgmjannwvopbva.trump.ldc325l.org.np — 未验证. 证据摘要: VirusTotal 9/91 (BitDefender, Chong Lua Dao, CyRadar, Fortinet, G-Data); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 85/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies xmtfgmjannwvopbva.trump.ldc325l.org.np as a generic phishing threat. This domain was designed to deceive users into divulging sensitive information, though no specific brand impersonation or drainer kit has been confirmed. Its suspicious structure and subdomain naming pattern suggest an intent to appear legitimate while hosting fraudulent content.
Technical analysis reveals that this domain was created on April 23, 2026, and is registered through an unidentified registrar. It resolves to IP address 135.235.195.147 and uses a Let's Encrypt SSL certificate (R12) to appear secure. VirusTotal data shows 2 out of 95 security vendors flagging it as malicious, and it appears on 3 security blocklists. The page title was "Index of /", indicating a directory listing that could host phishing files. The domain is not listed on Google Safe Browsing, but its blocklist presence and low detection rate suggest it was active but not widely reported.
Currently, the domain is offline and has been taken down. This is a positive outcome, but residual risk remains as similar domains may reappear. Users should avoid interacting with any communications referencing this domain and report any phishing attempts. PhishDestroy recommends monitoring for related subdomains and maintaining updated security software to detect future threats.
威胁响应 Pipeline
公共封禁名单状态
域名情报
技术细节DNS、SSL SAN、时间戳
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。