Phishing detection: erutjhpk.login.dwmnhsqa.wccheck-6b3c4826-a.santandertelephony-yfcowbeta.bimp-bot.duckdns.org
Banco Santander Investigate
Domain
erutjhpk.login.dwmnhsqa.wccheck-6b3c4826-a.santandertelephony-yfcowbeta.bimp-bot.duckdns.org6336 CT hosts on apex
IP
195.234.4.57
URL
https://erutjhpk.login.dwmnhsqa.wccheck-6b3c4826-a.santande…
Cert
-
Phishunt analysis Beta
32
medium suspicion suspiciousheuristic risk score · not a probability
Why?
- +6.1 Google Safe Browsing
- +5.3 Keyword match
- +5.1 Site cluster
- +3.5 ASN reputation
- +3.4 Shared IP cluster
- +2.2 Country mismatch
- +1.6 Young domain
- +1.1 No CSP header
- +1.1 No HSTS header
- +0.7 Bulletproof DNS
- +0.6 Long domain
- +0.6 Deep subdomain
- +0.6 Suspicious TLD
- +0.4 Hyphens
16 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting
Site impersonates Santander bank telephony services using a deeply nested DuckDNS domain with obfuscated random labels. Flagged by Google Safe Browsing for social engineering. Shares IP and infrastructure with other Santander phishing domains on HOSTLAB LLC in Ukraine.
Deep subdomainGoogle Safe BrowsingKeyword match
AI-generated from stored detector signals - the AI never visited the site. · 2026-08-08 · confidence 80%
Domain & Network
Whois
Registrar
Gandi SAS
Network
IP
195.234.4.57
Country
Ukraine
Hosting
HOSTLAB LLC
ASN
AS51734
TLS Cert
-
External detection
Google Safe Browsing
GSB category: SOCIAL_ENGINEERING
CleanOpenPhish · PhishTank · TweetFeed · urlscan.io
Campaign
Requests
Resources
Observables
Related websites
Report this phishing
Submit to blocklists
urlscan
VirusTotal
Whois
ipinfo
Greynoise