# PhishDestroy threat dossier — belvingatefin.com ================================================================ Fetched: 2026-04-23 07:58:00 UTC Canonical: https://phishdestroy.io/domain/belvingatefin.com/ ## VERDICT ---------------------------------------------------------------- ACTIVE THREAT — multiple warning signs Composite threat score: 50/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 14/95 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Lionic, Netcraft, Sophos, VIPRE URLQuery: 2 detections ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 163.61.188.9 (US, Staten Island) ASN: AS153568 NEW DHAKA HARDWARE Hosting org: MIT Registrar: TuringSign Inc. d/b/a Cosmotown Nameservers: dns1.lytehosting.com, dns2.lytehosting.com, dns3.lytehosting.com, dns4.lytehosting.com, ns1.cprapid.com, ns2.cprapid.com Registered: 2026-02-07 Page title: AAR Global Construction HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R13 Expires: 2026-06-25 Status: INVALID chain Fingerprint: 3f5b05bfd8bb7c0d33f141d17030eac26f06a9e6cdc03d1cbc82002a7fb9a451 Subject Alternative Names (related infrastructure — often same operator): - aarglobalconstructionltd.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-02-07 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-23 07:41:15 UTC (by PhishDestroy tracker) First reported: 2026-04-23 04:42:07 UTC (abuse notice filed) Last verified: 2026-04-23 10:00:05 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019db8a3-e7ff-77a7-93e5-f977eb145c6c/ URLQuery: https://urlquery.net/report/b9991146-a71f-40de-8919-eac9b6fa0f7f Wayback Machine: https://web.archive.org/web/*/belvingatefin.com crt.sh CT logs: https://crt.sh/?q=%25.belvingatefin.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=belvingatefin.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/belvingatefin.com URLhaus: https://urlhaus.abuse.ch/host/belvingatefin.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-23 07:41:41 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies belvingatefin.com as an active fake-investment phishing domain with an elevated risk level. This site impersonates a legitimate financial gateway to steal user credentials and inject malware under the guise of high-return investment opportunities. Users are urged to avoid any interaction with the domain and report it immediately. This domain was flagged by 14 of 95 VirusTotal security vendors, resolves to IP 163.61.188.9, and was registered on February 07, 2026 through TuringSign Inc. d/b/a Cosmotown. Let’s Encrypt issued the SSL certificate, but the site remains absent from major public blocklists and carries low trust scores across multiple threat-intelligence feeds. To stay safe, block belvingatefin.com at the network firewall and DNS level, avoid clicking any links or downloading attachments from the site, and verify any financial offers through official channels. If you suspect exposure, run a full antivirus scan and change passwords only on trusted devices. Report the domain to your security team and local cybercrime units to help reduce further victimization. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260423-EDE220 Favicon MD5: 4202078cf30064b08e3d824e3ff7c607 TLS cert SHA-256: 3f5b05bfd8bb7c0d33f141d17030eac26f06a9e6cdc03d1cbc82002a7fb9a451 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/belvingatefin.com/ JSON API: https://api.destroy.tools/v1/check?domain=belvingatefin.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io