es4dr56tyuikdf6g-dp9xyf4hhc53.edgeone.dev

This edgeone.dev subdomain hosts a phishing page designed to harvest credentials.

Critical Risk
Phishing / Credential Theft

At a glance

Antivirus · registration · identity
Antivirus detections
16 flagged
15 malicious · 1 suspicious
BitDefender
Domain registration
UnavailableRegistered
UnavailableAt scan time
Operator identity
Missing
No independently verifiable operator identity
Verified factsSaved with this scan
  1. 15 engines classified the URL as malicious and 1 as suspicious; 47 returned harmless, 29 returned undetected, and 0 returned no usable result.
  2. Operator identity: Missing. No independently verifiable operator identity
  3. Google Safe Browsing returned no listed threat categories for this address at scan time.
  4. The site presented a valid TLSv1.3 certificate at scan time.

Intelligence

The domain es4dr56tyuikdf6g-dp9xyf4hhc53.edgeone.dev served a single-hop landing page that antivirus engines overwhelmingly labeled malicious, aligning with a phishing operation that attempts to capture visitor credentials.

Evidence Map

Reputation
Concern

One or more reputation sources recorded a concern

Identity
Limited

No independently verifiable operator identity

Behavior
Unavailable

No usable behavior observation was saved

History
Unavailable

No reliable registration history was saved

Risk Factors
  • 115 antivirus engines flagged the URL as malicious
  • 2Primary harm is credential harvesting via phishing page

Domain and hosting profile

The reported address is the exact subdomain es4dr56tyuikdf6g-dp9xyf4hhc53.edgeone.dev reached over plain HTTP. A valid TLSv1.3 certificate was presented, yet the hosting IP carried only a minimal abuse-confidence score of 2/100 from a single report.

Visitor path and page behavior

The saved redirect chain contained one hop with no cross-domain, homoglyph, or internationalized-domain indicators. No traffic indexing was recorded for the address.

Security-vendor findings

Fifteen antivirus engines classified the URL as malicious and one returned a suspicious result, while Google Safe Browsing listed no threat categories at scan time.

Threat category and harm mechanism

The page archetype is an unknown landing page whose supported harm mechanism is credential harvesting via phishing.

Web Research

No independently sourced claims were found for this report.

Threat Detection

Antivirus results, browser warnings, isolated page observations, and the threat pattern identified in this report.

Antivirus distribution
Recorded engine classifications, not a blanket clean bill
92 engines
Malicious15
Suspicious1
Harmless47
Undetected29
No result0
Antivirus consensus

Antivirus engine results

Result date Jul 21, 2026
Detection matrix
16 engines flagged this URL

This scan saved classifications from an antivirus network of 92 engines. Each malicious or suspicious classification is listed below by engine name and should be weighed with the rest of the report.

15Malicious1Suspicious47Harmless29Undetected0No result92Engines
0
of 92
BitDefender
Malicious· phishing
Cluster25
Malicious· phishing
ESET
Malicious· phishing
Forcepoint ThreatSeeker
Malicious· phishing
Fortinet
Malicious· phishing
G-Data
Malicious· phishing
Gridinsoft
Malicious· phishing
Kaspersky
Malicious· phishing
Lionic
Malicious· phishing
Rising
Malicious· phishing
SOCRadar
Malicious· phishing
Sophos
Malicious· phishing
VIPRE
Malicious· phishing
Webroot
Malicious· malicious
Yandex Safebrowsing
Malicious· phishing
URLQuery
Suspicious· suspicious

16 antivirus engines flagged this URL. A single classification is not consensus by itself. Review its label together with the page, identity, behavior, and history evidence shown in this report.

Threat pattern
Phishing / Credential Theft
Threat tags
phishing
Top reasons

Evidence behind this threat profile

2 reasons
  1. 115 antivirus engines flagged the URL as malicious
  2. 2Primary harm is credential harvesting via phishing page
Scam-Type Likelihood

1 of 21 categories showed signals

This profile separates the site's primary threat from other patterns supported by the saved page evidence, public research, and security findings.

Top match: Phishing
Phishing
High likelihood
92/100
  • 15/92 AV engines flagged the domain as phishing
  • Specific detections: BitDefender phishing, Cluster25 phishing, ESET phishing, Forcepoint ThreatSeeker phishing, Fortinet phishing, G-Data phishing

Technical Details

Identity, domain, infrastructure, and connection facts saved with this scan.

July 21, 2026 at 11:04 AM UTC

Identity

6 facts
Operator
Missing
On-domain email
Not observed
Other email
Not observed
Phone
Not observed
Postal address
Not observed
Social profiles
Not observed

Domain

8 facts
Domain age
Unavailable
Registered
Unavailable
Registrar
Unavailable
Expires
Unavailable
WHOIS updated
Unavailable
Registrant
Unavailable
Registration country
Unavailable
WHOIS privacy
Unavailable

Infrastructure

14 facts
HTTPS
Valid certificate
TLS protocol
TLSv1.3
Certificate issuer
DigiCert, Inc. · DigiCert Secure Site OV G2 TLS CN RSA4096 SHA256 2022 CA1
Certificate subject
*.edgeone.dev
Certificate valid from
Nov 19, 2025
Certificate valid to
Nov 19, 2026
Network address
43.174.246.29
ASN
Unavailable
Hosting organization
ACEVILLE PTE.LTD.
Country
SG
Server
Unavailable
Site platform
Unavailable
IP reputation
2% confidence · 1 reports
Tor exit node
No

Connections

13 facts
Scan scope
Domain
Destination host
es4dr56tyuikdf6g-dp9xyf4hhc53.edgeone.dev
Redirects
1
Cross-domain redirect
No
Redirect status codes
302 → 404
Lookalike characters
Not observed
Internationalized domain
No
Page response
404
Observation coverage
Unavailable
Extracted links
Unavailable
Unique IPs contacted
Unavailable
Countries contacted
Unavailable
Referenced domains
0

What to do

1
Before interacting
Do not sign in

Do not visit or enter any credentials.

2
If you already interacted

If you entered a password, change it on the official service by typing its known address yourself, enable two-factor authentication, and review recent account activity. Contact your bank if you also entered payment details.

Final Verdict

Do not sign in

Why this verdict

The URL was classified malicious for phishing because 15 antivirus engines flagged it and the page matches the credential-harvesting archetype.

Recommendation

Do not visit or enter any credentials.

Key evidence

  1. 115 antivirus engines flagged the URL as malicious
  2. 2Primary harm is credential harvesting via phishing page
  3. 315 engines classified the URL as malicious and 1 as suspicious; 47 returned harmless, 29 returned undetected, and 0 returned no usable result.
Evidence: strongScope: DomainFresh scan: July 21, 2026 at 11:04 AM UTC

Safety FAQ

Is es4dr56tyuikdf6g-dp9xyf4hhc53.edgeone.dev safe to use?+

The URL was classified malicious for phishing because 15 antivirus engines flagged it and the page matches the credential-harvesting archetype.

What should I do about es4dr56tyuikdf6g-dp9xyf4hhc53.edgeone.dev?+

Do not visit or enter any credentials.

How old is es4dr56tyuikdf6g-dp9xyf4hhc53.edgeone.dev?+

A reliable public registration date was not available for es4dr56tyuikdf6g-dp9xyf4hhc53.edgeone.dev.

What if I already interacted with es4dr56tyuikdf6g-dp9xyf4hhc53.edgeone.dev?+

If you entered a password, change it on the official service by typing its known address yourself, enable two-factor authentication, and review recent account activity. Contact your bank if you also entered payment details.

When was this report updated?+

This report reflects the scan completed July 21, 2026 at 11:04 AM UTC.