Scam Detective
Domain

daestfestifalkrlon.com

First seen May 23, 2026

Suspicious
  • No SSL certificate
  • 1 community report from users
reported_togetherreported_togetherreported_togethercampaign co-memberDomain: ardotcharleybuking.com — Suspicious, 0 complaintsardotcharleybukin…Domain: masteringruneterra.com — Suspicious, 0 complaintsmasteringruneterr…Domain: prnt.sc — Suspicious, 0 complaintsprnt.scPhone: 8443374133 — Low Activity, 0 complaints8443374133Domain: daestfestifalkrlon.com — Suspicious, 0 complaintsDomaindaestfestifalkrlon.comHigh RiskSuspiciousConsumer ComplaintsLow ActivityNode size = complaint volume

Campaign Intelligence

This cluster centers on 4 connected domains identified through shared infrastructure and registration patterns. The domains include prnt.sc, daestfestifalkrlon.com, masteringruneterra.com, ardotcharleybuking.com. The connected infrastructure includes 1 phone numbers (8443374133) with 0 FTC complaints. If you receive a call or text from any of these numbers, do not engage. Hang up immediately and do not call back. Never provide personal information or make payments to unknown callers. Do not cl...

Details

Registrar
CNOBIN INFORMATION TECHNOLOGY LIMITED
Registration Date
8/18/2025
First Seen
5/23/2026

Related Domains

Community Reports

Problem with a website. Not sure if my PC is infected or if the site has a problem So I am trying to access [this website (Mastering Runeterra)](https://masteringruneterra.com/meta-tier-list/), which is a website that shows meta decks for the video game Legends of Runeterra. Suddenly without any noticable reason I couldn't access the website anymore and was show just an empty screen with a captcha [picture of the screen](https://prnt.sc/MaPtw_iVJ5zZ). When I tried to click on the captcha I got a prompt that I was supposed to copy something in my terminal [screenshot of the prompt](https://prnt.sc/ZvrOujNdEXjG). On top of that a script was automatically pasted into my clipboard so I assume if I would have open my terminal I would downloaded malware. Now to my question: Is this a server side problem that I see this fake captcha and a sign that the server or domain or whatever it is got hacked or is it a sign that I have some malware on my PC that forward me to this screen? I checked the [networkanalysis](https://prnt.sc/X5DszzBxNyAm) and from what I saw so far is 1. The broswer gets the url I try to access 2. It then gets a subdocument from the url "daestfestifalkrlon.com" 3. After that it gets a subdocument from "ardotcharleybuking.com" 4. This domain then sends Javascript scripts. According from my research the ardot domain is a C2 domain of a Latrodectus botnet. Sorry if the question is dumb, I have some IT knowledge but I really lack any knowledge when it comes to malware and I just want to be sure.

22 days ago1 upvote

Share Your Experience

What's Your Exposure?

Know your risk exposure to this message with a Thorough Analysis. It returns a detailed report covering the complaint history, your data breach exposure, related scam entities, and risk signals tied to this email message. Check the box and enter your email address now.