# PhishDestroy threat dossier — atlastradingproltd.com ================================================================ Fetched: 2026-07-27 04:52:36 UTC Canonical: https://phishdestroy.io/domain/atlastradingproltd.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 93/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 5/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, CRDF, Fortinet, Gridinsoft, Netcraft URLQuery: 3 detections Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 5.182.209.88 Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED !!! REGISTRAR INTEGRITY ALERT — NiceNIC !!! NiceNIC International: over 90% of its registered domains are associated with illegal content; documented systematic abuse-report non-response. Primary sources: https://phishdestroy.io/nicenic-real https://phishdestroy.io/nicenic-verdict Nameservers: ns1.pwxs.net, ns2.pwxs.net Registered: 2026-05-04 Expires: 2027-05-04 Page title: Atlas Trading Pro | Innovative Trading App ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-10-03 Status: INVALID chain Fingerprint: 2ef910effa70d3558b7b650f0b365ef4e2058875764a01e95a9b6ffb8f3dc26b ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-04 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 05:13:41 UTC (by PhishDestroy tracker) First reported: 2026-07-27 03:58:46 UTC (abuse notice filed) Last verified: 2026-07-27 06:43:54 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa18e-7b69-746f-9143-a58408e98182/ URLQuery: https://urlquery.net/report/397239f8-0768-4890-95f2-c3f4b01d1ec3 Wayback Machine: https://web.archive.org/web/*/atlastradingproltd.com crt.sh CT logs: https://crt.sh/?q=%25.atlastradingproltd.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=atlastradingproltd.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/atlastradingproltd.com URLhaus: https://urlhaus.abuse.ch/host/atlastradingproltd.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 05:18:02 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] atlastradingproltd.com High-Risk Generic Phishing Domain Alert atlastradingproltd.com is currently classified as a high-risk generic phishing domain, based on multiple threat intelligence sources as of July 27, 2026. This domain appears on at least one security blocklist, specifically flagged by PhishDestroy, and has been detected by 5 of 91 security vendors according to VirusTotal. The domain remains active and was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on May 04, 2026. Its infrastructure resolves to IP address 5.182.209.88, with nameservers ns1.pwxs.net and ns2.pwxs.net, which may be indicative of a hosting provider often associated with questionable or malicious activity, though further analysis is required to confirm this. There is no information available regarding the site's content, targeted brand, or specific phishing kit. No Safe Browsing, OTX, trust score, page title, or SSL certificate details are provided, limiting the ability to assess the sophistication or nature of the fraudulent operation. The evidence currently points to the domain being actively used for generic phishing, but the exact tactics, techniques, or intended victims remain undetermined due to the absence of website analysis and additional context. Defenders should treat this domain as a credible threat, given its presence on blocklists and multiple detection engines. Immediate blocking at the network perimeter and inclusion in security awareness campaigns are recommended. Monitoring for related infrastructure, such as the associated IP address and nameservers, may help identify further malicious activity. Any user interaction with this domain should be considered high risk. Further investigation into hosting details and potential related domains is advised to map the broader threat landscape. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-4C6BC3 Favicon MD5: ae1c7ce5f501f13bb37bda2f7dfd0801 TLS cert SHA-256: 2ef910effa70d3558b7b650f0b365ef4e2058875764a01e95a9b6ffb8f3dc26b ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/atlastradingproltd.com/ JSON API: https://api.destroy.tools/v1/check?domain=atlastradingproltd.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 202,551 domains (77,973 alive under monitoring, 123,547 confirmed takedowns/dead). Site: https://phishdestroy.io