# PhishDestroy threat dossier — butterfieldgrpbk.online.ekpsuckass.com ================================================================ Fetched: 2026-06-27 14:56:39 UTC Canonical: https://phishdestroy.io/domain/butterfieldgrpbk.online.ekpsuckass.com/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Credential Phishing ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 5/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Gridinsoft, Kaspersky, PhishFort, SOCRadar Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 198.251.84.141 (US, Cheyenne) Hosting org: AS53667 FranTech Solutions Registrar: NameCheap, Inc. Nameservers: ns3.asurahosting.com, ns4.asurahosting.com Registered: 2026-04-16 Expires: 2027-04-16 HTTP response: 530 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-09-07 Status: INVALID chain Fingerprint: 000b76ae5bdbb4691d3b569a10891e75bbec0601417cf5a78f0e6e6d94282a80 Subject Alternative Names (related infrastructure — often same operator): - autodiscover.butterfieldgrpbk.online - butterfieldgrpbk.online - cpanel.butterfieldgrpbk.online - cpcalendars.butterfieldgrpbk.online - cpcontacts.butterfieldgrpbk.online - mail.butterfieldgrpbk.online - webdisk.butterfieldgrpbk.online - webmail.butterfieldgrpbk.online - www.butterfieldgrpbk.online - www.butterfieldgrpbk.online.ekpsuckass.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-16 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-06-10 23:18:45 UTC (by PhishDestroy tracker) First reported: 2026-06-10 21:19:53 UTC (abuse notice filed) Last verified: 2026-06-27 16:20:35 UTC Neutralised: 2026-06-13 12:42:16 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019eb365-fa38-74da-88c8-5769ccc62058/ URLQuery: https://urlquery.net/report/9448d780-3056-4a2f-821f-e9efdda0cfd0 Wayback Machine: https://web.archive.org/web/*/butterfieldgrpbk.online.ekpsuckass.com crt.sh CT logs: https://crt.sh/?q=%25.butterfieldgrpbk.online.ekpsuckass.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=butterfieldgrpbk.online.ekpsuckass.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/butterfieldgrpbk.online.ekpsuckass.com URLhaus: https://urlhaus.abuse.ch/host/butterfieldgrpbk.online.ekpsuckass.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-25 14:53:52 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Infrastructure analysis indicates that butterfieldgrpbk.online.ekpsuckass.com is associated with a generic phishing operation consistent with fake login credential harvesting. The observed naming structure and subdomain composition are characteristic of phishing infrastructure designed to imitate legitimate online services and capture user authentication data. No verified brand attribution or specialized credential theft kit has been identified from the available intelligence; however, the domain exhibits multiple indicators commonly associated with active phishing campaigns and unauthorized credential collection activity. Technical indicators support a high-risk assessment. The domain is currently active and was created on April 16, 2026. Registration records show the domain was registered through NameCheap, Inc. Resolution data maps the infrastructure to IP address 198.251.84.141 located in the United States within AS53667. Security telemetry shows that 5 out of 95 security vendors flag the domain as malicious on VirusTotal. The domain appears on 1 security blocklist and has been blocked by PhishDestroy. SSL services are present through a Let's Encrypt certificate (YR1), a common configuration frequently observed across both legitimate and malicious internet infrastructure. No information is available indicating removal from security filtering systems, and the domain remains operational at the time of assessment. Current status remains active, increasing the likelihood of continued phishing exposure. Given the combination of active infrastructure, security detections, blocklist inclusion, and credential-harvesting characteristics, the residual risk is assessed as high. Defensive actions should include immediate blocking of the domain and associated IP address 198.251.84.141, monitoring for related indicators across network telemetry, reviewing authentication logs for suspicious access attempts, and conducting user awareness notifications where exposure is suspected. Organizations should inspect email, web proxy, DNS, and endpoint records for historical interactions with the domain. Continued monitoring is recommended because active phishing infrastructure may be repurposed, expanded, or migrated to related domains while remaining operational. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260610-443A99 Favicon MD5: b8a0bf372c762e966cc99ede8682bc71 TLS cert SHA-256: 000b76ae5bdbb4691d3b569a10891e75bbec0601417cf5a78f0e6e6d94282a80 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/butterfieldgrpbk.online.ekpsuckass.com/ JSON API: https://api.destroy.tools/v1/check?domain=butterfieldgrpbk.online.ekpsuckass.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 170,872 domains (12,736 alive under monitoring, 157,726 confirmed takedowns/dead). Site: https://phishdestroy.io