# PhishDestroy threat dossier — apexguardscapital.com ================================================================ Fetched: 2026-07-21 09:12:06 UTC Canonical: https://phishdestroy.io/domain/apexguardscapital.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 97/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 8/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Fortinet, Hunt.io Intelligence, Netcraft, SOCRadar, Sophos Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 198.251.88.6 (LU, Luxembourg) ASN: AS53667 FranTech Solutions Hosting org: FranTech Solutions Registrar: Realtime Register B.V. Nameservers: ["ns1.asurahosting.com", "ns2.asurahosting.com"] HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-09-30 Status: INVALID chain Fingerprint: 501c952eb71f16b1b4a05e2feb3a3504c4fa42a4d9c47aea213d21dd90e4e018 Subject Alternative Names (related infrastructure — often same operator): - anchorstonetrust.com - internpol.com - nexthorizoncapitals.com - smartdeliverycompany.com - wbapexrises.com - www.anchorstonetrust.com.internpol.com - www.apexguardscapital.com.internpol.com - www.nexthorizoncapitals.com.internpol.com - www.smartdeliverycompany.com.internpol.com - www.wbapexrises.com.internpol.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-19 13:01:06 UTC (by PhishDestroy tracker) Last verified: 2026-07-21 08:20:22 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-19 15:51:32 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] apexguardscapital.com - Generic Phishing Investigation The domain apexguardscapital.com is currently classified as a high‑risk generic phishing site and remains active as of the report date. Automated analysis shows the site returns HTTP 200, indicating a live web server. Threat intelligence indicates it has been blocked by the PhishDestroy platform and is listed on one external security blocklist. VirusTotal scans have recorded detections by eight of ninety‑one antivirus or URL‑filtering vendors, confirming that multiple security products recognize malicious behavior associated with the domain. No additional infrastructure details such as hosting IP addresses, registrar information, or ASN data are available from the provided intelligence, and the underlying content of the site has not been examined. Consequently, the precise phishing vector, credential‑harvesting mechanisms, or target brand remain undefined. Defenders should prioritize immediate containment by adding apexguardscapital.com to web‑filter deny lists, enforcing DNS sink‑hole rules, and ensuring that endpoint security solutions are updated to reflect the eight vendor detections reported by VirusTotal. Continuous monitoring for any new host or IP associations is advised, as well as periodic re‑query of reputation services to capture any changes in detection status. Organizations should also educate users about unsolicited communications that may reference financial or investment themes, given the domain’s naming pattern, and encourage verification of any links before credential entry. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 31b384fe74cb1e6efc24aba97e054fd2 TLS cert SHA-256: 501c952eb71f16b1b4a05e2feb3a3504c4fa42a4d9c47aea213d21dd90e4e018 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/apexguardscapital.com/ JSON API: https://api.destroy.tools/v1/check?domain=apexguardscapital.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 187,511 domains (57,616 alive under monitoring, 128,244 confirmed takedowns/dead). Site: https://phishdestroy.io