# PhishDestroy threat dossier — bulging-assets.com ================================================================ Fetched: 2026-07-27 04:52:01 UTC Canonical: https://phishdestroy.io/domain/bulging-assets.com/ ## VERDICT ---------------------------------------------------------------- ACTIVE THREAT — multiple warning signs Composite threat score: 54/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 4/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, CRDF, Gridinsoft, Netcraft AlienVault OTX: 1 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 104.21.35.39 Registrar: TuringSign Inc. d/b/a Cosmotown Nameservers: audrey.ns.cloudflare.com, colin.ns.cloudflare.com Registered: 2025-09-09 Expires: 2026-09-09 Page title: Bulgingassets ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE1 Expires: 2026-10-12 Status: INVALID chain Fingerprint: fb6892ce5a1976cea6ad9a9318d64ba24e5ed279fa32bbd7722c0df4d04bb12d ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-09-09 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 05:31:31 UTC (by PhishDestroy tracker) Last verified: 2026-07-27 06:50:28 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa1a9-4c76-71a8-83f0-591add64453f/ URLQuery: https://urlquery.net/report/c949afc3-776f-4973-a24e-a84bc9cc792f Wayback Machine: https://web.archive.org/web/*/bulging-assets.com crt.sh CT logs: https://crt.sh/?q=%25.bulging-assets.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=bulging-assets.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/bulging-assets.com URLhaus: https://urlhaus.abuse.ch/host/bulging-assets.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 05:31:58 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is bulging-assets.com a phishing domain? Analysis of bulging-assets.com shows it is actively used for phishing. The domain resolves to IP address 172.67.213.44 and is hosted on Cloudflare infrastructure, as indicated by its authoritative nameservers audrey.ns.cloudflare.com and colin.ns.cloudflare.com. Registration data reveals the domain was created on September 09, 2025 and was registered through TuringSign Inc. d/b/a Cosmotown, a registrar known to be used by malicious actors. The domain appears on a single security blocklist and is currently blocked by the PhishDestroy service, confirming that at least one reputable anti‑phishing feed has flagged it. VirusTotal scans report that 4 of 91 security vendors have flagged the domain, providing independent confirmation of malicious intent. The domain’s status is listed as active, meaning the infrastructure remains reachable and capable of delivering phishing content. No additional intelligence such as SSL certificate details, HTTP response codes, Safe Browsing verdicts, or page title information is available in the current dataset, leaving those aspects unverified. Defenders should prioritize blocking network traffic to 172.67.213.44 and adding bulging-assets.com to local deny lists. Monitoring for any new detections from additional vendors or blocklists is advised, as the low vendor count suggests the threat may be emerging. Given the registrar’s history and the presence on a phishing blocklist, organizations should treat any email or web interaction involving this domain as malicious and educate users to avoid credential submission on the site. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: eb230157db5329f2e6a97b5c2b73693c TLS cert SHA-256: fb6892ce5a1976cea6ad9a9318d64ba24e5ed279fa32bbd7722c0df4d04bb12d ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/bulging-assets.com/ JSON API: https://api.destroy.tools/v1/check?domain=bulging-assets.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 202,551 domains (77,973 alive under monitoring, 123,547 confirmed takedowns/dead). Site: https://phishdestroy.io