# PhishDestroy threat dossier — capital-lp.com ================================================================ Fetched: 2026-07-29 23:05:20 UTC Canonical: https://phishdestroy.io/domain/capital-lp.com/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 64/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 4/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Fortinet, Gridinsoft, LevelBlue Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 213.111.156.15 (NL, Haarlem) ASN: AS43641 SOLLUTIUM EU Sp z.o.o. Hosting org: AMS Registrar: SOLLUTIUM LLC Nameservers: ns1.unverified-domain.vsys.name, ns2.unverified-domain.vsys.name Registered: 2026-07-08 Expires: 2027-07-08 Page title: Unverified Domain HTTP response: 200 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-08 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-28 18:40:22 UTC (by PhishDestroy tracker) First reported: 2026-07-28 16:50:07 UTC (abuse notice filed) Last verified: 2026-07-30 01:04:07 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa997-8d73-749e-a21b-b1deeeeef5ea/ URLQuery: https://urlquery.net/report/29f21d80-a142-43f8-a6aa-399af194d9f2 Wayback Machine: https://web.archive.org/web/*/capital-lp.com crt.sh CT logs: https://crt.sh/?q=%25.capital-lp.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=capital-lp.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/capital-lp.com URLhaus: https://urlhaus.abuse.ch/host/capital-lp.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 18:45:40 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is capital-lp.com a Phishing Site Targeting Financial Analysis of the domain capital-lp.com indicates high-risk phishing activity based on observable infrastructure and detection data. The domain was registered on July 8, 2026, through SOLLUTIUM LLC, a registrar frequently associated with newly created malicious domains. It currently resolves to the IP address 213.111.156.15, though no additional hosting or ASN details are available for further attribution. The nameservers ns1.unverified-domain.vsys.name and ns2.unverified-domain.vsys.name are linked to a provider known for hosting unverified and often malicious domains, reinforcing the domain's suspicious classification. As of July 28, 2026, capital-lp.com appears on three security blocklists, including PhishDestroy, MetaMask, and SEAL, which specifically flag phishing and fraudulent financial sites. VirusTotal reports that 4 out of 91 security vendors detect the domain as malicious, though the exact nature of the threat—whether credential harvesting, fake login portals, or other phishing tactics—remains unconfirmed due to the absence of page content analysis. No brand or targeted service has been explicitly identified in available data, and the domain's content has not been reviewed for visual or functional indicators. Defenders should treat this domain as active and malicious. Network-level blocking is recommended, particularly for financial and enterprise environments where credential theft poses significant risk. If internal logs show connections to 213.111.156.15 or the domain itself, immediate investigation is warranted to assess potential exposure. Given the domain's recent registration and ongoing detections, continued monitoring for new infrastructure or shifts in hosting is advised. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260728-C64E99 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/capital-lp.com/ JSON API: https://api.destroy.tools/v1/check?domain=capital-lp.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,510 domains (93,335 alive under monitoring, 99,913 confirmed takedowns/dead). Site: https://phishdestroy.io