# PhishDestroy threat dossier — credencechartered.com ================================================================ Fetched: 2026-05-12 10:06:28 UTC Canonical: https://phishdestroy.io/domain/credencechartered.com/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 64/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 8/92 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Fortinet, G-Data, Lionic, Netcraft ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 198.251.84.200 (LU, Luxembourg) ASN: AS53667 FranTech Solutions Hosting org: FranTech Solutions Registrar: Global Domain Group LLC Nameservers: ns5.asurahosting.com, ns5.my-control-panel.com, ns6.asurahosting.com, ns6.my-control-panel.com Registered: 2026-05-12 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-12 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-12 01:14:58 UTC (by PhishDestroy tracker) Earliest abuse rec: 2026-05-11 22:16:54 UTC — PREDATES current WHOIS registration; retained from a previous registration cycle of the same domain name Last verified: 2026-05-12 07:40:01 UTC Neutralised: 2026-05-12 03:44:03 UTC Current status: taken down (registrar suspended or DNS dead) Note: one or more events above predate the WHOIS creation date. This typically means the same domain name was previously registered, detected, dropped, and then re-registered by a new party. PhishDestroy preserves the full historical record for operator-attribution research even when the underlying infrastructure changes hands. ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e1919-afdb-71a7-8c78-9070ab6f0641/ URLQuery: https://urlquery.net/report/775c215f-318a-41d8-b20d-2a1386f947aa Wayback Machine: https://web.archive.org/web/*/credencechartered.com crt.sh CT logs: https://crt.sh/?q=%25.credencechartered.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=credencechartered.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/credencechartered.com URLhaus: https://urlhaus.abuse.ch/host/credencechartered.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-12 01:15:34 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] credencechartered.com has been identified by PhishDestroy as an elevated-risk credential harvesting domain. It is currently active and functioning as a phishing site designed to trick users into surrendering sensitive login credentials under the guise of a legitimate organization. The domain's rapid registration, combined with its low trust indicators, makes it a high-value target for attackers leveraging social engineering tactics. credencechartered.com was registered on September 09, 2025, through Global Domain Group LLC, a registrar with minimal identity verification protocols. It resolves to IP address 198.251.84.200 and is protected by a Let's Encrypt SSL certificate, which attackers commonly exploit to appear legitimate. Security analysis via VirusTotal reveals that 8 out of 95 leading antivirus and threat intelligence engines have flagged this domain as malicious or phishing-related. The domain exhibits no meaningful web presence, no corporate footprint, and no verifiable institutional history, which are critical red flags in domain safety assessments. Additionally, the use of a newly created domain (less than 30 days old) and hosting on a shared IP space with a history of abuse further elevates the risk profile. Users encountering this domain should immediately cease all interaction, avoid submitting any personal, financial, or login information, and report the domain to their IT security team or via trusted threat reporting platforms such as Google Safe Browsing, PhishTank, or your organization’s incident response channel. Credential harvesting operates by mimicking trusted entities—never enter credentials on unvalidated login forms. Organizations are advised to block access to this domain at the network level using DNS filtering or firewall rules, and to monitor internal systems for signs of credential compromise or unauthorized access attempts. Proactive user awareness training emphasizing skepticism of newly registered domains and encrypted phishing sites is strongly recommended. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260511-5985A6 Favicon MD5: 2d255898db178f009f588fa84fff7ad1 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/credencechartered.com/ JSON API: https://api.destroy.tools/v1/check?domain=credencechartered.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 148,350 domains (36,961 alive under monitoring, 111,111 confirmed takedowns/dead). Site: https://phishdestroy.io