# PhishDestroy threat dossier — accessfortune.live ================================================================ Fetched: 2026-07-27 04:45:10 UTC Canonical: https://phishdestroy.io/domain/accessfortune.live/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 10/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, BitDefender, CRDF, CyRadar, Fortinet, G-Data, Kaspersky, Lionic, Netcraft, Sophos URLQuery: 2 detections Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 5.182.208.206 Registrar: REGISTRAR_NOT_FOUND Nameservers: ns1.zencorehost.com, ns2.zencorehost.com Registered: 2026-05-20 Page title: accessfortune.live ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-09-20 Status: INVALID chain Fingerprint: dfce5ebd15fa7f9329803c79d57cd1793561c886d3900b49dca0eb5a9161add2 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-20 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 04:52:45 UTC (by PhishDestroy tracker) First reported: 2026-07-27 03:11:03 UTC (abuse notice filed) Last verified: 2026-07-27 06:40:53 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa19d-365e-705e-87cc-50c3e523b6d0/ URLQuery: https://urlquery.net/report/cb520b91-571f-40f9-9425-d052c8f1e19b Wayback Machine: https://web.archive.org/web/*/accessfortune.live crt.sh CT logs: https://crt.sh/?q=%25.accessfortune.live Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=accessfortune.live AlienVault OTX: https://otx.alienvault.com/indicator/domain/accessfortune.live URLhaus: https://urlhaus.abuse.ch/host/accessfortune.live/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 04:55:04 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] accessfortune.live Safety Check — Phishing Detected accessfortune.live is a newly registered Internet domain that has been linked to a high‑risk generic phishing campaign. The domain was created on 20 May 2026 and is currently active. WHOIS data shows registration through NameSilo, LLC and authoritative name servers ns1.zencorehost.com and ns2.zencorehost.com. DNS resolution points exclusively to the IPv4 address 5.182.208.206, which is the sole hosting endpoint observed for this infrastructure. Multi‑engine analysis on VirusTotal indicates that 10 of 91 anti‑malware scanners flag the domain as malicious, reinforcing the suspicion of phishing use. The same domain is listed on a commercial phishing blocklist operated by PhishDestroy and appears on one additional security blocklist, reflecting that at least two independent threat‑intelligence sources have classified it as hostile. No further public reputation services or safe‑browsing checks have been disclosed. The evidence base is limited to registration metadata, DNS hosting, and detection counts; no payload samples, page titles, SSL certificates, or HTTP response details have been published. Consequently, the exact phishing lure, targeted brand, or victim demographics remain unknown. Analysts should treat any traffic to or from 5.182.208.206 as potentially malicious and consider immediate blocking at the network perimeter. It is advisable to monitor the domain for changes in DNS records, to query additional sandbox services for content snapshots, and to update endpoint protection signatures with the observed detection identifiers. Organizations employing URL filtering should add accessfortune.live to deny lists, and SOC teams should correlate any internal alerts that reference the domain or its IP address with this intelligence to reduce exposure. [Updates since narrative was generated:] - VirusTotal detections: now 10/91 (narrative was written when count was lower) ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-161980 Favicon MD5: b9e9cfccd15ebf492b4410f605037a10 TLS cert SHA-256: dfce5ebd15fa7f9329803c79d57cd1793561c886d3900b49dca0eb5a9161add2 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/accessfortune.live/ JSON API: https://api.destroy.tools/v1/check?domain=accessfortune.live Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 202,499 domains (77,921 alive under monitoring, 123,547 confirmed takedowns/dead). Site: https://phishdestroy.io