# PhishDestroy threat dossier — casibom-girisyap-mobil.com ================================================================ Fetched: 2026-07-26 22:57:44 UTC Canonical: https://phishdestroy.io/domain/casibom-girisyap-mobil.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 92/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain Flagging vendors: Fortinet Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.96.3 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: CloudFlare, Inc. Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED !!! REGISTRAR INTEGRITY ALERT — NiceNIC !!! NiceNIC International: over 90% of its registered domains are associated with illegal content; documented systematic abuse-report non-response. Primary sources: https://phishdestroy.io/nicenic-real https://phishdestroy.io/nicenic-verdict Nameservers: chris.ns.cloudflare.com, gail.ns.cloudflare.com Registered: 2026-07-21 Expires: 2027-07-21 Page title: Just a moment... HTTP response: 403 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-10-19 Status: INVALID chain Fingerprint: fdbca8f998840172c111acde3c4402b376be69a078266c5606f39feabd5be540 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-21 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-26 15:40:41 UTC (by PhishDestroy tracker) Last verified: 2026-07-27 00:56:48 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f9ea6-76b0-738a-b645-9ac6c6bece5a/ Wayback Machine: https://web.archive.org/web/*/casibom-girisyap-mobil.com crt.sh CT logs: https://crt.sh/?q=%25.casibom-girisyap-mobil.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=casibom-girisyap-mobil.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/casibom-girisyap-mobil.com URLhaus: https://urlhaus.abuse.ch/host/casibom-girisyap-mobil.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-26 15:40:52 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] casibom-girisyap-mobil.com Safety Check — Phishing Campaign The domain casibom-girisyap-mobil.com was registered on July 21 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED. It is delegated to Cloudflare DNS, using the authoritative name servers chris.ns.cloudflare.com and gail.ns.cloudflare.com, and resolves to the IPv4 address 188.114.96.3. At the time of assessment the domain remains active and has been blocked by the PhishDestroy service, indicating that it is already recognized as a malicious resource. VirusTotal analysis reports that 1 of 91 security vendors flagged the domain, providing a concrete detection signal, and the domain appears on a single external blocklist. No additional public intelligence such as Safe Browsing verdicts, Open Threat Exchange mentions, SSL certificate details, HTTP status codes, or page‑title information is available, so the exact content and phishing vector employed by the site cannot be confirmed from the current data set. The limited age of the domain—only five days old as of this report—combined with the early detection by multiple security mechanisms elevates its risk profile to high. Defenders should immediately add casibom-girisyap-mobil.com to internal blocklists and enforce DNS filtering to prevent resolution, monitor outbound traffic to the IP address 188.114.96.3, and consider sinkholing or redirecting any attempted connections. Continuous threat‑intel feed correlation is advised to capture any emerging indicators, such as new blocklist entries or additional vendor detections. Until a definitive takedown is confirmed, endpoint and network security controls should be configured to deny any communication with this domain, and incident response teams should be alerted to the potential for credential harvesting or other phishing‑related activity. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: fdbca8f998840172c111acde3c4402b376be69a078266c5606f39feabd5be540 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/casibom-girisyap-mobil.com/ JSON API: https://api.destroy.tools/v1/check?domain=casibom-girisyap-mobil.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 200,217 domains (87,433 alive under monitoring, 111,753 confirmed takedowns/dead). Site: https://phishdestroy.io