# PhishDestroy threat dossier — cloudshareit.top ================================================================ Fetched: 2026-05-14 16:37:20 UTC Canonical: https://phishdestroy.io/domain/cloudshareit.top/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 81/100 (PhishDestroy scoring — see methodology below) Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users (type: redirect_split) (score: 4/6) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 10/95 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Sophos Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.67.135.166 Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED !!! REGISTRAR INTEGRITY ALERT — NiceNIC !!! NiceNIC International: over 90% of its registered domains are associated with illegal content; documented systematic abuse-report non-response. Primary sources: https://phishdestroy.io/nicenic-real https://phishdestroy.io/nicenic-verdict Nameservers: charles.ns.cloudflare.com, liberty.ns.cloudflare.com Registered: 2026-02-09 Page title: Startpage - Private Search Engine. No Tracking. No Search History. ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-02-09 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-14 18:22:10 UTC (by PhishDestroy tracker) Last verified: 2026-05-14 19:20:38 UTC Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e2711-1fb7-7264-9a66-d51ea53599e4/ Wayback Machine: https://web.archive.org/web/*/cloudshareit.top crt.sh CT logs: https://crt.sh/?q=%25.cloudshareit.top Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=cloudshareit.top AlienVault OTX: https://otx.alienvault.com/indicator/domain/cloudshareit.top URLhaus: https://urlhaus.abuse.ch/host/cloudshareit.top/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-14 18:22:48 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy has identified cloudshareit.top as a credential theft domain designed to trick users into entering login details that are harvested by cybercriminals. This site masquerades as a legitimate cloud service, luring victims with familiar branding to capture usernames and passwords. Anyone who enters credentials on this page risks direct account takeover and potential financial loss if the same login is reused elsewhere. The domain uses HTTPS via a Let’s Encrypt certificate, giving it a deceptive appearance of legitimacy. This domain was flagged by 10 out of 95 security vendors on VirusTotal, and it has been added to at least one major threat blocklist. Domain registration records show it was created on February 09, 2026, just days ago, and is currently hosted on IP address 172.67.135.166. It was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar known for hosting a high volume of fraudulent domains. The site is already blocked by MetaMask, a leading crypto wallet, indicating early detection of blockchain-related threats. If you visited or entered any information on cloudshareit.top, immediately change your password on all related accounts—especially email, cloud services, and financial platforms—and enable multi-factor authentication where available. Do not trust browser warnings to bypass; this site is actively malicious. Report the domain to your IT team or security provider, clear your browser cache, and run a full antivirus scan. Share this alert with colleagues or contacts who may have visited the site. Stay safe by verifying any unexpected login prompts through official channels before entering credentials. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: d2285a78d0c4bb9f0202beaf287bafa4 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/cloudshareit.top/ JSON API: https://api.destroy.tools/v1/check?domain=cloudshareit.top Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 149,310 domains (36,954 alive under monitoring, 111,596 confirmed takedowns/dead). Site: https://phishdestroy.io