Phishing detection: erutjhpk.login.dwmnhsqa.wccheck-6b3c4826-a.santandertelephony-yfcowbeta.bimp-bot.duckdns.org

Banco Santander
https://erutjhpk.login.dwmnhsqa.wccheck-6b3c4826-a.santandertelephony-yfcowbeta.bimp-bot.duckdns.org Access site
Screenshot
Screenshot of erutjhpk.login.dwmnhsqa.wccheck-6b3c4826-a.santandertelephony-yfcowbeta.bimp-bot.duckdns.org
Investigate
Domain erutjhpk.login.dwmnhsqa.wccheck-6b3c4826-a.santandertelephony-yfcowbeta.bimp-bot.duckdns.org6336 CT hosts on apex
URL https://erutjhpk.login.dwmnhsqa.wccheck-6b3c4826-a.santande…
Phishunt analysis Beta
32 medium suspicion suspiciousheuristic risk score · not a probability
Why?
  • +6.1 Google Safe Browsing
  • +5.3 Keyword match
  • +5.1 Site cluster
  • +3.5 ASN reputation
  • +3.4 Shared IP cluster
  • +2.2 Country mismatch
  • +1.6 Young domain
  • +1.1 No CSP header
  • +1.1 No HSTS header
  • +0.7 Bulletproof DNS
  • +0.6 Long domain
  • +0.6 Deep subdomain
  • +0.6 Suspicious TLD
  • +0.4 Hyphens
16 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting

Site impersonates Santander bank telephony services using a deeply nested DuckDNS domain with obfuscated random labels. Flagged by Google Safe Browsing for social engineering. Shares IP and infrastructure with other Santander phishing domains on HOSTLAB LLC in Ukraine.

Deep subdomainGoogle Safe BrowsingKeyword match
AI-generated from stored detector signals - the AI never visited the site. · 2026-08-08 · confidence 80%
Domain & Network
Whois
Registrar Gandi SAS
Network
Country UkraineUkraine
Hosting HOSTLAB LLC
ASN AS51734
TLS Cert -
External detection Google Safe Browsing
GSB category: SOCIAL_ENGINEERING
CleanOpenPhish · PhishTank · TweetFeed · urlscan.io
Campaign
Report this phishing

Tracked from 2026-08-08 05:27 UTC  ·  Last refreshed 2026-08-28 03:30 UTC