# PhishDestroy threat dossier — api.www.fhmfdvkxcqvpn.pdwithchloe.com ================================================================ Fetched: 2026-07-22 12:43:27 UTC Canonical: https://phishdestroy.io/domain/api.www.fhmfdvkxcqvpn.pdwithchloe.com/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 50/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 5/91 security vendors flagged this domain Flagging vendors: BitDefender, G-Data, SOCRadar, Sophos, Webroot Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- Registrar: Squarespace Domains II LLC Nameservers: ["ns1.dns-parking.com", "ns2.dns-parking.com"] ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-19 13:00:11 UTC (by PhishDestroy tracker) Last verified: 2026-07-22 12:20:32 UTC Neutralised: 2026-07-20 00:25:45 UTC Current status: taken down (registrar suspended or DNS dead) ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-19 21:27:57 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] api.www.fhmfdvkxcqvpn.pdwithchloe.com: Confirmed Phishing Analysis of the domain api.www.fhmfdvkxcqvpn.pdwithchloe.com confirms its role as an active phishing infrastructure component, specifically functioning as a redirect endpoint. The domain is currently flagged by PhishDestroy, a security blocklist provider, and is listed on one known security blocklist as of July 19, 2026. VirusTotal scans indicate that 5 out of 91 security vendors classify this domain as malicious, providing corroborating evidence of its threat status. The domain remains operational, responding with an HTTP 301 redirect, which is a common technique used in phishing campaigns to forward victims to fraudulent landing pages or malicious payloads. Infrastructure analysis reveals no additional details regarding the hosting provider, autonomous system number (ASN), or geographic origin at this time. The exact content or target brand of the phishing campaign is not yet analysed, as no specific page title, brand impersonation, or scam type has been identified in available intelligence. The absence of further infrastructure details does not diminish the confirmed malicious status, as the domain’s inclusion on a security blocklist and detection by multiple security vendors provide sufficient evidence of its role in phishing operations. Defenders are advised to treat this domain as high-risk and implement immediate blocking at the network and endpoint levels. Given the HTTP 301 redirect behavior, organizations should also monitor for outbound connections to this domain, as it may serve as an intermediary in multi-stage phishing attacks. Further investigation into associated IP addresses and redirect targets is recommended to identify the full scope of the campaign. No additional brand or scam-specific indicators are available at this time, but the domain’s active status and detection history warrant continued vigilance. ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/api.www.fhmfdvkxcqvpn.pdwithchloe.com/ JSON API: https://api.destroy.tools/v1/check?domain=api.www.fhmfdvkxcqvpn.pdwithchloe.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 188,055 domains (57,500 alive under monitoring, 128,922 confirmed takedowns/dead). Site: https://phishdestroy.io