# PhishDestroy threat dossier — download-worksheets.net ================================================================ Fetched: 2026-07-31 19:25:25 UTC Canonical: https://phishdestroy.io/domain/download-worksheets.net/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 98/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 5/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.67.176.140 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: AppCroNix Infotech Private Limited, d/b/a VEBONIX.com Nameservers: james.ns.cloudflare.com, magdalena.ns.cloudflare.com Registered: 2026-07-19 Expires: 2027-07-19 Page title: Download Worksheets | Free Printable Worksheets PDF HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-10-17 Status: INVALID chain Fingerprint: 0e92cb5bde36d1c56833cc25923a87a1f8fb7876549923fac18a28d8ff5bb441 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-19 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-22 20:15:21 UTC (by PhishDestroy tracker) First reported: 2026-07-22 18:17:49 UTC (abuse notice filed) Last verified: 2026-07-31 20:20:32 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f8b09-6a4b-773c-b0fb-95001ac8db66/ URLQuery: https://urlquery.net/report/cf3dc6b0-8d0c-4e34-84d0-dde04ce77a07 Wayback Machine: https://web.archive.org/web/*/download-worksheets.net crt.sh CT logs: https://crt.sh/?q=%25.download-worksheets.net Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=download-worksheets.net AlienVault OTX: https://otx.alienvault.com/indicator/domain/download-worksheets.net URLhaus: https://urlhaus.abuse.ch/host/download-worksheets.net/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-22 20:15:36 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] download-worksheets.net Generic Education-Themed Phishing Domain Analysis of download-worksheets.net indicates an active phishing domain registered on July 19, 2026, through AppCroNix Infotech Private Limited (d/b/a VEBONIX.com). The domain currently resolves to IP address 172.67.176.140 and is hosted on Cloudflare nameservers james.ns.cloudflare.com and magdalena.ns.cloudflare.com. As of July 22, 2026, the domain appears on one security blocklist, having been flagged by PhishDestroy. No detections were recorded among the 95 vendors that scanned the domain on VirusTotal, though the absence of detections does not confirm safety. The domain's content and specific target remain unconfirmed, as no brand impersonation or phishing kit details have been identified in available intelligence. The name 'download-worksheets' suggests a possible education or academic-themed lure, but no evidence confirms this as the exact scam type. Infrastructure analysis reveals Cloudflare hosting, which is frequently used by both legitimate and malicious actors to obscure origin servers. The registrar, VEBONIX.com, has been associated with other recently registered domains under investigation for phishing activity, though no direct pattern has been established in this case. Defenders are advised to treat this domain as suspicious based on its recent registration, single blocklist appearance, and lack of prior reputation. Network-level blocking or monitoring of 172.67.176.140 is recommended until further analysis confirms its intent. Additional scrutiny of domains registered through the same registrar within the past 72 hours may reveal related infrastructure. No SSL certificate details or HTTP response codes were provided in available intelligence, limiting assessment of server-side behavior. The domain remains active, and continued monitoring is warranted. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260722-599F77 Favicon MD5: 000bf649cc8f6bf27cfb04d1bcdcd3c7 TLS cert SHA-256: 0e92cb5bde36d1c56833cc25923a87a1f8fb7876549923fac18a28d8ff5bb441 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/download-worksheets.net/ JSON API: https://api.destroy.tools/v1/check?domain=download-worksheets.net Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 196,669 domains (84,388 alive under monitoring, 27,268 confirmed neutralized). Site: https://phishdestroy.io