# PhishDestroy threat dossier — 26junverifieaqui.fwh.is ================================================================ Fetched: 2026-06-29 04:50:21 UTC Canonical: https://phishdestroy.io/domain/26junverifieaqui.fwh.is/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 92/100 (PhishDestroy scoring — see methodology below) Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users (type: redirect_split) (score: 3/6) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 20/91 security vendors flagged this domain Flagging vendors: BitDefender, Chong Lua Dao, Cluster25, CyRadar, ESET, Emsisoft, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Kaspersky, LevelBlue, Lionic, MalwareURL, Netcraft, OpenPhish, Seclookup, Sophos, URLQuery, Webroot Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 185.27.134.217 (GB, Gosforth) ASN: AS34119 Wildcard UK Limited Hosting org: I FastNet LTD Registrar: FreeWebHostingArea Nameservers: ns1.byet.org, ns2.byet.org, ns3.byet.org, ns4.byet.org Registered: 2024-11-01 Expires: 2026-11-01 HTTP response: 200 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2024-11-01 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-06-28 12:18:08 UTC (by PhishDestroy tracker) First reported: 2026-06-28 10:19:51 UTC (abuse notice filed) Last verified: 2026-06-29 06:45:09 UTC Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f0dbb-c881-759d-a2c0-9ee9877a057b/ URLQuery: https://urlquery.net/report/a6cb0a1f-9b8c-437c-aaa3-fba8c09f8821 Wayback Machine: https://web.archive.org/web/*/26junverifieaqui.fwh.is crt.sh CT logs: https://crt.sh/?q=%25.26junverifieaqui.fwh.is Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=26junverifieaqui.fwh.is AlienVault OTX: https://otx.alienvault.com/indicator/domain/26junverifieaqui.fwh.is URLhaus: https://urlhaus.abuse.ch/host/26junverifieaqui.fwh.is/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-28 12:26:06 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] 26junverifieaqui.fwh.is is an active phishing website designed to deceive users into providing confidential information, such as login credentials or personal data. The domain poses an elevated risk due to its use of deceptive tactics typical of credential theft campaigns. Users interacting with this domain may be exposed to fraudulent forms or links that attempt to harvest sensitive information. Analysis indicates that 26junverifieaqui.fwh.is was created recently, on November 01, 2024, and operates with an SSL certificate issued by ZeroSSL GmbH. The site resolves to IP address 185.27.134.217 and is currently listed on two security blocklists. VirusTotal reports that 18 out of 95 security vendors have flagged this domain for malicious activity. The domain has also been blocked by multiple threat intelligence sources, confirming its involvement in phishing operations. If a user has visited 26junverifieaqui.fwh.is or entered any credentials, immediate action is recommended. Change any passwords or credentials that may have been entered, enable multi-factor authentication where possible, and monitor associated accounts for unauthorized activity. It is also advisable to run a comprehensive malware scan on your device and report any suspicious findings to your organization’s security team. Avoid interacting with this domain further, as continued exposure may increase the risk of compromise. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260628-653882 Favicon MD5: b8a0bf372c762e966cc99ede8682bc71 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/26junverifieaqui.fwh.is/ JSON API: https://api.destroy.tools/v1/check?domain=26junverifieaqui.fwh.is Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 172,285 domains (13,593 alive under monitoring, 158,144 confirmed takedowns/dead). Site: https://phishdestroy.io