# PhishDestroy threat dossier — b73223085-49c6-4dca-a2f1-4722014079fb-dpi4fgipupcs.edgeone.dev ================================================================ Fetched: 2026-07-04 15:17:57 UTC Canonical: https://phishdestroy.io/domain/b73223085-49c6-4dca-a2f1-4722014079fb-dpi4fgipupcs.edgeone.dev/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 71/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 15/91 security vendors flagged this domain Flagging vendors: BitDefender, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Kaspersky, Lionic, OpenPhish, SOCRadar, Sophos, URLQuery, Webroot, Yandex Safebrowsing Public blocklists: listed on 2 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 43.174.247.29 (SG, Singapore) ASN: AS139341 ACE Hosting org: ACE Registrar: REGISTRAR_NOT_FOUND Nameservers: NS_NOT_FOUND Page title: Loading... HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: DigiCert, Inc. / DigiCert Secure Site OV G2 TLS CN RSA4096 SHA256 2022 CA1 Expires: 2026-11-19 Status: INVALID chain Fingerprint: 58de5b23bf5257e41d9ce59c9894bd034142d56ef120a640f4700cf84cf0619b Subject Alternative Names (related infrastructure — often same operator): - edgeone.dev ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-04 14:23:13 UTC (by PhishDestroy tracker) First reported: 2026-07-04 12:35:22 UTC (abuse notice filed) Last verified: 2026-07-04 17:15:49 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f2d14-7f13-7183-9c49-7b56dfd58ff0/ URLQuery: https://urlquery.net/report/3541ad42-9bc0-429e-baf4-0a847e61f9eb Wayback Machine: https://web.archive.org/web/*/b73223085-49c6-4dca-a2f1-4722014079fb-dpi4fgipupcs.edgeone.dev crt.sh CT logs: https://crt.sh/?q=%25.b73223085-49c6-4dca-a2f1-4722014079fb-dpi4fgipupcs.edgeone.dev Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=b73223085-49c6-4dca-a2f1-4722014079fb-dpi4fgipupcs.edgeone.dev AlienVault OTX: https://otx.alienvault.com/indicator/domain/b73223085-49c6-4dca-a2f1-4722014079fb-dpi4fgipupcs.edgeone.dev URLhaus: https://urlhaus.abuse.ch/host/b73223085-49c6-4dca-a2f1-4722014079fb-dpi4fgipupcs.edgeone.dev/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-04 14:24:45 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] This domain, b73223085-49c6-4dca-a2f1-4722014079fb-dpi4fgipupcs.edgeone.dev, is flagged as a high-risk credential harvesting phishing threat. Analysis indicates the infrastructure is actively targeting users to extract sensitive login credentials, financial details, or personal information through deceptive interfaces. The threat type is classified as generic_phishing with a focus on credential theft, a common tactic in large-scale phishing campaigns. Infrastructure analysis reveals the domain resolves to the IP address 43.174.247.29 and is currently active. Security vendors on VirusTotal report 12 out of 95 detections, signaling a significant level of concern among threat intelligence providers. The SSL certificate is issued by DigiCert, Inc., which may lend an appearance of legitimacy but does not mitigate the malicious intent. The page title, 'Loading...', suggests a placeholder or obfuscation technique to delay detection while the phishing content is dynamically loaded. No creation date is provided, but the domain's active status and detection count indicate recent malicious activity. To mitigate risks associated with this credential harvesting phishing domain, organizations should immediately block access to the domain and its resolving IP address at the network perimeter. Endpoint protection systems should be updated to include the domain and IP in their blocklists. Users should be educated on recognizing phishing attempts, particularly those using delayed loading techniques or legitimate-looking SSL certificates. Security teams should monitor for any indicators of compromise, such as unauthorized access attempts or unusual login activity, and conduct a thorough review of logs for connections to 43.174.247.29. If credentials were entered on this domain, immediate password resets and multi-factor authentication enforcement are recommended. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260704-62BF1C Favicon MD5: 2a2b3dccda589896e35cc3c75f3b5998 TLS cert SHA-256: 58de5b23bf5257e41d9ce59c9894bd034142d56ef120a640f4700cf84cf0619b ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/b73223085-49c6-4dca-a2f1-4722014079fb-dpi4fgipupcs.edgeone.dev/ JSON API: https://api.destroy.tools/v1/check?domain=b73223085-49c6-4dca-a2f1-4722014079fb-dpi4fgipupcs.edgeone.dev Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 174,640 domains (13,109 alive under monitoring, 160,697 confirmed takedowns/dead). Site: https://phishdestroy.io