# PhishDestroy threat dossier — airtec-solution.com ================================================================ Fetched: 2026-07-21 11:39:58 UTC Canonical: https://phishdestroy.io/domain/airtec-solution.com/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 61/100 (PhishDestroy scoring — see methodology below) Targeted brand: Microsoft ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 4/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, ESET, Fortinet, SOCRadar Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- Registrar: E & Enterprise Cloud - Sole Proprietorship L.L.C Nameservers: ["ns1.ultahost.com", "ns2.ultahost.com", "ns3.ultahost.com", "ns4.ultahost.com"] HTTP response: 200 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-19 13:00:00 UTC (by PhishDestroy tracker) Last verified: 2026-07-21 12:25:50 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-19 22:13:37 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] airtec-solution.com — Active Microsoft 365 Credential Phishing Analysis of airtec-solution.com as of July 19, 2026 identifies it as an active phishing domain targeting Microsoft 365 credentials. The domain is currently resolving with an HTTP 200 status, indicating a live server. Infrastructure review shows a single MX record pointing to airtec-solution.com with priority 0, a configuration commonly exploited to receive stolen login data directly. The domain appears on one security blocklist and is flagged by 4 of 91 security vendors on VirusTotal, confirming detection by multiple independent engines. No brand or phishing kit has been conclusively linked to the domain at this stage, and the exact content of the site remains unanalysed. However, the presence of an MX record combined with active phishing detections strongly suggests an email-based credential harvesting operation. Defenders are advised to block the domain at the DNS and proxy levels, monitor inbound email traffic for links to airtec-solution.com, and review logs for connections from internal assets. Given the domain's active status and confirmed detections, this infrastructure poses a high risk to enterprise authentication security. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 5613add4c96586f1f0345c56e1b1bea3 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/airtec-solution.com/ JSON API: https://api.destroy.tools/v1/check?domain=airtec-solution.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 187,516 domains (57,259 alive under monitoring, 128,610 confirmed takedowns/dead). Site: https://phishdestroy.io