# PhishDestroy threat dossier — capital-excel.ltd ================================================================ Fetched: 2026-08-01 11:52:04 UTC Canonical: https://phishdestroy.io/domain/capital-excel.ltd/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 84/100 (PhishDestroy scoring — see methodology below) Targeted brand: MetaMask ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/91 security vendors flagged this domain Flagging vendors: CRDF, Netcraft AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 82.197.80.62 (US, Boston) ASN: AS47583 Hostinger International Limited Hosting org: Hostinger International Limited Registrar: HOSTINGER operations, UAB Nameservers: cosmos.dns-parking.com, nova.dns-parking.com Registered: 2026-06-19 Expires: 2027-06-19 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-06-19 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-28 20:27:40 UTC (by PhishDestroy tracker) First reported: 2026-07-28 18:27:36 UTC (abuse notice filed) Last verified: 2026-08-01 13:07:16 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa9f2-58a8-75c5-b320-8adb818164d8/ URLQuery: https://urlquery.net/report/70b180cc-b697-4450-a72b-7b51f59220d4 Wayback Machine: https://web.archive.org/web/*/capital-excel.ltd crt.sh CT logs: https://crt.sh/?q=%25.capital-excel.ltd Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=capital-excel.ltd AlienVault OTX: https://otx.alienvault.com/indicator/domain/capital-excel.ltd URLhaus: https://urlhaus.abuse.ch/host/capital-excel.ltd/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 21:01:19 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] capital-excel.ltd Safety Check — Generic Phishing Detected The domain capital-excel.ltd is currently identified as an active threat associated with generic phishing. Multiple independent sources have flagged this domain: it is blocked by PhishDestroy, MetaMask, and SEAL, and is listed on three separate security blocklists. This convergence of detections across different vendors and blocklists is a significant indicator of malicious use. The domain was registered through HOSTINGER operations, UAB and became active on June 19, 2026. Its DNS configuration uses nameservers cosmos.dns-parking.com and nova.dns-parking.com, and it currently resolves to IP address 82.197.80.62. VirusTotal results show that 2 out of 91 security vendors detect this domain as malicious, reinforcing the phishing classification. At this time, there is no information about the website's specific content, target brand, or the nature of any phishing kit in use. No additional metadata regarding SSL, HTTP status, or page title is available, so the exact tactics and lures deployed remain unconfirmed. Defenders should treat capital-excel.ltd as high risk. Immediate action is recommended: block access to this domain at the network level, monitor for related activity originating from 82.197.80.62, and update end-user awareness regarding potential phishing threats referencing this domain. Since the domain remains active as of July 28, 2026, continued monitoring for further malicious infrastructure associated with this domain is advised. If new indicators or content evidence become available, further technical analysis should be conducted to refine detection and response strategies. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260728-DF5997 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/capital-excel.ltd/ JSON API: https://api.destroy.tools/v1/check?domain=capital-excel.ltd Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,907 domains (90,693 alive under monitoring, 27,319 confirmed neutralized). Site: https://phishdestroy.io