Phishing detection: erutjhpk.login.dwmnhsqa.wccheck-6b3c4826-a.santandertelephony-yfcowbeta.bimp-bot.duckdns.org

Banco Santander
https://erutjhpk.login.dwmnhsqa.wccheck-6b3c4826-a.santandertelephony-yfcowbeta.bimp-bot.duckdns.org Access site
Screenshot
Screenshot of erutjhpk.login.dwmnhsqa.wccheck-6b3c4826-a.santandertelephony-yfcowbeta.bimp-bot.duckdns.org
Investigate
Domain erutjhpk.login.dwmnhsqa.wccheck-6b3c4826-a.santandertelephony-yfcowbeta.bimp-bot.duckdns.org6336 CT hosts on apex
URL https://erutjhpk.login.dwmnhsqa.wccheck-6b3c4826-a.santande…
Phishunt analysis Beta
23 low suspicionheuristic risk score · not a probability
Why?
  • +6.1 Google Safe Browsing
  • +5.3 Keyword match
  • +3.5 ASN reputation
  • +2.2 Country mismatch
  • +1.1 No CSP header
  • +1.1 No HSTS header
  • +1.0 Young domain
  • +0.7 Unrecognised DNS provider
  • +0.6 Long domain
  • +0.6 Deep subdomain
  • +0.6 Suspicious TLD
  • +0.4 Hyphens
14 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting

Site impersonates Santander bank telephony services using a deeply nested DuckDNS domain with obfuscated random labels. Flagged by Google Safe Browsing for social engineering. Shares IP and infrastructure with other Santander phishing domains on HOSTLAB LLC in Ukraine.

Deep subdomainGoogle Safe BrowsingKeyword match
AI-generated from stored detector signals - the AI never visited the site. · 2026-08-08 · confidence 80%
Domain & Network
Whois
Registrar Gandi SAS
Network
Country UkraineUkraine
Hosting HOSTLAB LLC
ASN AS51734
TLS Cert -
External detection Google Safe Browsing
GSB category: SOCIAL_ENGINEERING
CleanOpenPhish · PhishTank · TweetFeed · urlscan.io
Report this phishing

Tracked from 2026-08-08 05:27 UTC  ·  Last refreshed 2026-09-20 15:30 UTC