# PhishDestroy threat dossier — 1rg12gji6hjkhaz.top ================================================================ Fetched: 2026-07-24 14:48:08 UTC Canonical: https://phishdestroy.io/domain/1rg12gji6hjkhaz.top/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 83/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/91 security vendors flagged this domain Flagging vendors: ESET, Fortinet Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 103.224.212.108 (AU, Beaumaris) ASN: AS133618 Trellian Pty. Limited Hosting org: Trellian Pty. Limited Registrar: Dynadot LLC Nameservers: ["5014.ns1.abovedomains.com.", "5014.ns2.abovedomains.com."] Page title: 1rg12gji6hjkhaz.top HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-10-10 Status: INVALID chain Fingerprint: d606146be9ca84d6dbba5e231aa06c3a3213e52711a3a66d442e62d0158e225e Subject Alternative Names (related infrastructure — often same operator): - 06264.army - 071201.academy - 10021.gdn - 11215.cc - 11271.cc - 11351.cc - 465274.lol - 465474.lol - 619185.lol - 619343.com - 639270.lol - 63b58badf5e21379.com - 689780.lol - 987121.vip - 998xpj15.top ... +27 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-19 13:01:30 UTC (by PhishDestroy tracker) Last verified: 2026-07-24 16:20:23 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-22 14:41:02 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is 1rg12gji6hjkhaz.top a phishing site? Analysis of the domain 1rg12gji6hjkhaz.top, observed on 22 July 2026, indicates active malicious infrastructure. The domain resolves to the IPv4 address 103.224.212.108, which is hosted in Australia and attributed to Trellian Pty. Limited. DNS configuration lists the authoritative nameservers 5014.ns1.abovedomains.com. and 5014.ns2.abovedomains.com., and the MX record points to park-mx.above.com with priority 10, suggesting the domain is capable of receiving email. Registration was performed through Dynadot LLC, a known registrar that does not inherently mitigate abuse. The web server presents an Apache HTTP Server banner and serves HTTP responses with status code 200, returning a page whose title is identical to the domain name. TLS termination is provided by a Let's Encrypt certificate (certificate profile YR1), confirming that encrypted connections are offered. Threat intelligence sources place the domain on a single security blocklist and record that it is blocked by the PhishDestroy service. VirusTotal reports that 2 of 91 scanning engines flag the domain, indicating that at least some automated detectors have identified malicious characteristics. No additional public detections, such as from Google Safe Browsing or OTX, are referenced in the current data set. While the available evidence confirms that the domain is actively hosting content and is associated with phishing‑related blocklists, the specific payload, target brand, or phishing kit employed on the site has not been disclosed. Consequently, the precise victim profile and the exact method of credential harvesting remain uncertain. Defenders should treat 1rg12gji6hjkhaz.top as hostile. Recommended mitigations include adding the domain and its resolved IP address to blocklists at the network perimeter, configuring email gateways to reject or quarantine messages originating from the MX host, and enforcing TLS inspection to observe the underlying HTTP content. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: d606146be9ca84d6dbba5e231aa06c3a3213e52711a3a66d442e62d0158e225e ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/1rg12gji6hjkhaz.top/ JSON API: https://api.destroy.tools/v1/check?domain=1rg12gji6hjkhaz.top Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 189,326 domains (58,547 alive under monitoring, 129,180 confirmed takedowns/dead). Site: https://phishdestroy.io