# PhishDestroy threat dossier — 98tanf.net ================================================================ Fetched: 2026-07-26 14:48:57 UTC Canonical: https://phishdestroy.io/domain/98tanf.net/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 45/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.65.235.97 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: Gname.com Pte. Ltd. Nameservers: a.share-dns.com, b.share-dns.net, ns1.gname-dns.com, ns2.gname-dns.com Registered: 2024-06-07 Expires: 2027-06-07 Page title: 点击继续|淘宝闪购 微信 支付宝 微博 百度 爱奇艺 快手 小红书 抖音 HTTP response: 503 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2024-06-07 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-22 19:54:18 UTC (by PhishDestroy tracker) First reported: 2026-07-22 17:58:57 UTC (abuse notice filed) Last verified: 2026-07-26 16:20:28 UTC Neutralised: 2026-07-23 00:27:28 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f8af5-8769-7024-a9fb-77277138e8c5/ URLQuery: https://urlquery.net/report/952c3088-843d-40df-b367-bac3d005f246 Wayback Machine: https://web.archive.org/web/*/98tanf.net crt.sh CT logs: https://crt.sh/?q=%25.98tanf.net Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=98tanf.net AlienVault OTX: https://otx.alienvault.com/indicator/domain/98tanf.net URLhaus: https://urlhaus.abuse.ch/host/98tanf.net/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-22 19:55:20 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is 98tanf.net a Phishing Site? Analysis of the domain 98tanf.net, created on June 07, 2024, indicates that it is currently active and associated with a generic phishing campaign. The domain resolves to the IP address 172.65.235.97 and is hosted on infrastructure that appears in a single security blocklist. Nameserver records list a.share-dns.com, b.share-dns.net, ns1.gname-dns.com, and ns2.gname-dns.com, and the registration was performed through Gname.com Pte. Ltd. VirusTotal records show that the domain has been examined by 95 scanning engines, none of which returned a detection at the time of the last check. The domain is also listed by the PhishDestroy blocklist. No additional public threat intelligence sources such as OTX, Google Safe Browsing, or SSL/TLS certificate transparency logs have been observed for this domain, and no page title or content analysis is publicly available. The lack of detections in VirusTotal and the presence on a single blocklist do not constitute a definitive assessment of risk; the observed infrastructure and registrar details are consistent with other malicious phishing operators. Defenders should continue to monitor the domain for changes in classification, incorporate the IP address 172.65.235.97 and the domain name into outbound and inbound filtering rules, and ensure that any traffic to the domain is logged for forensic review. Periodic re‑scanning on VirusTotal and checking reputable blocklists such as PhishDestroy, as well as querying DNS reputation services, are recommended to detect any escalation in malicious activity. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260722-B44BBD ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/98tanf.net/ JSON API: https://api.destroy.tools/v1/check?domain=98tanf.net Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 198,198 domains (67,517 alive under monitoring, 129,132 confirmed takedowns/dead). Site: https://phishdestroy.io