# PhishDestroy threat dossier — cr-agrmobile09.info ================================================================ Fetched: 2026-07-27 04:53:36 UTC Canonical: https://phishdestroy.io/domain/cr-agrmobile09.info/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 83/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.96.3 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: CloudFlare, Inc. Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED !!! REGISTRAR INTEGRITY ALERT — NiceNIC !!! NiceNIC International: over 90% of its registered domains are associated with illegal content; documented systematic abuse-report non-response. Primary sources: https://phishdestroy.io/nicenic-real https://phishdestroy.io/nicenic-verdict Nameservers: jake.ns.cloudflare.com, wally.ns.cloudflare.com Registered: 2026-07-20 Expires: 2027-07-20 HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-10-18 Status: INVALID chain Fingerprint: 21845872f1dc49f0b3fe3c234fe37018de883bccbc3ab168883d01f27d3e75aa ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-20 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-26 15:21:16 UTC (by PhishDestroy tracker) First reported: 2026-07-26 14:15:18 UTC (abuse notice filed) Last verified: 2026-07-27 06:41:53 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f9ea6-76b5-76a8-a032-f4d6a5364bfd/ URLQuery: https://urlquery.net/report/2c81c8bc-cbfb-436a-aa11-ff40fc7d427d Wayback Machine: https://web.archive.org/web/*/cr-agrmobile09.info crt.sh CT logs: https://crt.sh/?q=%25.cr-agrmobile09.info Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=cr-agrmobile09.info AlienVault OTX: https://otx.alienvault.com/indicator/domain/cr-agrmobile09.info URLhaus: https://urlhaus.abuse.ch/host/cr-agrmobile09.info/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-26 15:26:50 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] cr-agrmobile09.info used for generic phishing campaign This domain, cr-agrmobile09.info, was registered on 20 July 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and immediately began resolving to the IP address 188.114.97.3. The authoritative name servers are jake.ns.cloudflare.com and wally.ns.cloudflare.com, indicating Cloudflare DNS hosting. The domain entered security monitoring shortly after creation and has been listed on one public blocklist. PhishDestroy has actively blocked the domain, and the blocklist entry confirms its association with a generic phishing campaign. VirusTotal has processed the hostname with 91 scanning engines; none of the engines reported a detection at the time of analysis. While the absence of detections does not guarantee the site is benign, it does suggest that the payload, if any, has not yet been identified by the scanned vendors. No public evidence has been found for Safe Browsing, Open Threat Exchange, SSL certificate details, HTTP response codes, or trust‑score metrics, and the page title has not been disclosed. Consequently, the current visibility into the site’s content and delivery mechanisms remains limited. The primary indicators of compromise are the recent registration date, the use of Cloudflare name servers, the single blocklist entry, and the PhishDestroy block. Defenders should add cr-agrmobile09.info to inbound and outbound URL filtering policies, monitor DNS queries for the domain and its associated IP, and enforce strict email gateway rules for messages containing links to the domain. Because the hosting infrastructure uses Cloudflare, any rapid changes to the IP or name‑server configuration may be employed to evade detection; continuous re‑evaluation of the domain’s status on blocklists and scanning services is recommended. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260726-3A7B92 TLS cert SHA-256: 21845872f1dc49f0b3fe3c234fe37018de883bccbc3ab168883d01f27d3e75aa ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/cr-agrmobile09.info/ JSON API: https://api.destroy.tools/v1/check?domain=cr-agrmobile09.info Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 202,551 domains (77,973 alive under monitoring, 123,547 confirmed takedowns/dead). Site: https://phishdestroy.io