# PhishDestroy threat dossier — aiweek.pakistan.gov.pk ================================================================ Fetched: 2026-07-22 07:50:13 UTC Canonical: https://phishdestroy.io/domain/aiweek.pakistan.gov.pk/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 73/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 203.101.184.84 (PK, Lahore) ASN: AS9541 Cyber Internet Services (Pvt) Ltd. Hosting org: Broadband Services Page title: Indus AI Week 2026 | Pakistan's Official National Platform for AI | Pakistan's Official National Platform for AI HTTP response: 301 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: GoGetSSL / GoGetSSL RSA DV CA Expires: 2026-11-23 Status: INVALID chain Fingerprint: 2a036eecca6a117b9a5c68096791e5f3747d37f508d5abf9ab1b15ae02e3d43b Subject Alternative Names (related infrastructure — often same operator): - abc.gov.pk - adm.cga.gov.pk - admin.inmolaech.gov.pk - agfp.gov.pk - agp.gov.pk - agpr.gov.pk - alp.gov.pk - api.gov.pk - asfportal.gov.pk - aviation.gov.pk - awci.edu.pk - becs.gov.pk - beta.nhmp.gov.pk - business.gov.pk - cci.gov.pk ... +224 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-19 13:01:18 UTC (by PhishDestroy tracker) Last verified: 2026-07-22 08:20:21 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-19 14:34:51 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] aiweek.pakistan.gov.pk — Government-Themed Phishing Domain Report This domain, aiweek.pakistan.gov.pk, is under investigation for government-themed phishing activity as of July 19, 2026. Infrastructure analysis reveals a 301 HTTP redirect, indicating the domain may be configured to forward visitors to another destination, a common tactic in phishing campaigns to obscure the final malicious endpoint. The domain is currently flagged on one security blocklist by PhishDestroy, though no additional blocklist or vendor detections are recorded at this time. A VirusTotal scan conducted by 91 vendors returned no flags, but this absence of detections does not confirm the domain's legitimacy or safety. The domain remains active, and its association with a government subdomain (pakistan.gov.pk) suggests potential targeting of users expecting official communications. No specific brand impersonation, phishing kit, or scam type has been confirmed in available data. Defenders should treat this domain as suspicious pending further analysis, particularly if observed in unsolicited emails, messages, or network traffic. Monitoring for additional blocklist inclusions or vendor detections is recommended, as is reviewing logs for connections to this domain or its redirect targets. If the domain is encountered in a production environment, isolation and further investigation are advised to determine intent and potential compromise. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 28284054c3e92cb7bdc356bd089e2031 TLS cert SHA-256: 2a036eecca6a117b9a5c68096791e5f3747d37f508d5abf9ab1b15ae02e3d43b ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/aiweek.pakistan.gov.pk/ JSON API: https://api.destroy.tools/v1/check?domain=aiweek.pakistan.gov.pk Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 187,759 domains (57,336 alive under monitoring, 128,779 confirmed takedowns/dead). Site: https://phishdestroy.io