# PhishDestroy threat dossier — app.vertexcapituspro.com ================================================================ Fetched: 2026-07-27 05:34:24 UTC Canonical: https://phishdestroy.io/domain/app.vertexcapituspro.com/ ## VERDICT ---------------------------------------------------------------- ACTIVE THREAT — multiple warning signs Composite threat score: 45/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 207.180.224.194 Registrar: TuringSign Inc. d/b/a Cosmotown Nameservers: sam.gzdns.vip, son.gzdns.vip Registered: 2026-05-04 Expires: 2027-05-04 Page title: Vertexcapitus – Empowering Your Financial Journey ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-10-01 Status: INVALID chain Fingerprint: 862f9bb96d5a70d58776e63514495c6edb964b83ddae5450b090276471fda835 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-04 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 05:05:15 UTC (by PhishDestroy tracker) First reported: 2026-07-27 03:51:39 UTC (abuse notice filed) Last verified: 2026-07-27 06:50:43 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa18e-f923-7707-8388-78dd5187a836/ URLQuery: https://urlquery.net/report/42abc8cd-0b85-4356-ad00-2c81156d2bae Wayback Machine: https://web.archive.org/web/*/app.vertexcapituspro.com crt.sh CT logs: https://crt.sh/?q=%25.app.vertexcapituspro.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=app.vertexcapituspro.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/app.vertexcapituspro.com URLhaus: https://urlhaus.abuse.ch/host/app.vertexcapituspro.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 05:09:35 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] app.vertexcapituspro.com — Credential Phishing Infrastructure This investigation report documents the domain app.vertexcapituspro.com, registered on May 4, 2026, through COSMOTOWN, INC., and currently classified as active credential phishing infrastructure. As of July 27, 2026, the domain remains unresolved in Safe Browsing checks but is flagged by PhishDestroy and appears on one security blocklist, indicating confirmed malicious categorization by at least one vendor. Infrastructure analysis reveals the domain utilizes nameservers sam.gzdns.vip and son.gzdns.vip, a pattern observed in other phishing campaigns leveraging dynamic DNS providers for rapid domain rotation. The domain resolves to the IP address 207.180.224.194, though no associated autonomous system or hosting provider details are currently available for further attribution. VirusTotal scans conducted by 91 security vendors returned no detections; however, this absence does not confirm benign status and may reflect delayed or incomplete detection coverage. No evidence links the domain to a specific brand, kit, or phishing campaign subtype (e.g., payment fraud, account takeover, or business email compromise). The page title and exact content remain unanalyzed, precluding definitive classification of the targeted service or impersonated entity. Defenders are advised to treat this domain as high-risk infrastructure pending further analysis. Recommended actions include blocking resolution at the DNS level, monitoring for connections to 207.180.224.194, and submitting additional samples to detection vendors to improve coverage. Given the domain’s recent registration and active status, continued monitoring of its hosting environment and nameserver associations is warranted to identify related infrastructure. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-6E1A80 Favicon MD5: abc0eee7a70706db2d9f7567cae911db TLS cert SHA-256: 862f9bb96d5a70d58776e63514495c6edb964b83ddae5450b090276471fda835 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/app.vertexcapituspro.com/ JSON API: https://api.destroy.tools/v1/check?domain=app.vertexcapituspro.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 202,849 domains (78,271 alive under monitoring, 123,547 confirmed takedowns/dead). Site: https://phishdestroy.io