# PhishDestroy threat dossier — 100089v.com ================================================================ Fetched: 2026-07-25 20:02:29 UTC Canonical: https://phishdestroy.io/domain/100089v.com/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 61/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 15/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Lionic, SOCRadar, Sophos, VIPRE, Webroot Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- Registrar: Gname.com Pte. Ltd. Nameservers: ["a.share-dns.com", "b.share-dns.net"] HTTP response: 301 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-19 12:59:54 UTC (by PhishDestroy tracker) Last verified: 2026-07-25 20:20:23 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-22 11:56:13 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] 100089v.com Fake Account Verification Phishing Alert Analysis conducted on July 22, 2026, identifies 100089v.com as an active phishing domain registered through Gname.com Pte. Ltd. Infrastructure review shows the domain is hosted on nameservers a.share-dns.com and b.share-dns.net, a configuration commonly observed in low-reputation hosting environments. The domain presents a 301 HTTP redirect, suggesting it is being used as an intermediary to forward victims to a secondary malicious endpoint, though the final destination remains unconfirmed at this time. SSL certification is provided by Let's Encrypt, a neutral certificate authority that does not validate content legitimacy. Detection data indicates moderate vendor awareness: 15 of 91 security engines on VirusTotal currently flag the domain as malicious. Additionally, the domain appears on a single blocklist maintained by PhishDestroy, a specialized anti-phishing service. While the exact brand being impersonated has not been definitively identified through available metadata, the domain's structure and naming convention align with credential-harvesting campaigns targeting account verification processes. No evidence links this domain to a specific commercial brand or service. Defenders are advised to treat 100089v.com as high-risk infrastructure. Network-level blocking is recommended for organizations using PhishDestroy or compatible threat feeds. Security teams should monitor for connections to this domain, particularly in contexts involving user authentication or account management workflows. Further analysis of the redirect chain and final landing page is necessary to determine the precise phishing kit or brand impersonation in use. Given the domain's active status and detection profile, continued monitoring is warranted to assess potential campaign evolution. ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/100089v.com/ JSON API: https://api.destroy.tools/v1/check?domain=100089v.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 192,698 domains (62,884 alive under monitoring, 128,255 confirmed takedowns/dead). Site: https://phishdestroy.io