# PhishDestroy threat dossier — ekatabahuddeshiysanstha.org ================================================================ Fetched: 2026-07-28 09:02:09 UTC Canonical: https://phishdestroy.io/domain/ekatabahuddeshiysanstha.org/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 16/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CTX AI, CyRadar, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Lionic, SOCRadar, Sophos, VIPRE, Webroot URLQuery: 2 detections AlienVault OTX: 7 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 204.11.59.88 (US, Provo) ASN: ASAS46606 UNIFIEDLAYER-AS-1 - Unified Layer, US Hosting org: AS46606 Unified Layer Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com Nameservers: ns1.bh-24.webhostbox.net, ns2.bh-24.webhostbox.net Registered: 2018-03-17 Expires: 2027-03-17 Page title: Not Acceptable! HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-09-29 Status: INVALID chain Fingerprint: 24328fc058080231d02501a2fbacff88494becefad500ede6623356d450b9926 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2018-03-17 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-18 17:52:55 UTC (by PhishDestroy tracker) First reported: 2026-07-18 15:58:37 UTC (abuse notice filed) Last verified: 2026-07-28 08:20:33 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f75ed-dceb-7178-8511-c324621bccbd/ URLQuery: https://urlquery.net/report/6760d38d-67b0-4dde-97e3-5cf800ac388a Wayback Machine: https://web.archive.org/web/*/ekatabahuddeshiysanstha.org crt.sh CT logs: https://crt.sh/?q=%25.ekatabahuddeshiysanstha.org Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=ekatabahuddeshiysanstha.org AlienVault OTX: https://otx.alienvault.com/indicator/domain/ekatabahuddeshiysanstha.org URLhaus: https://urlhaus.abuse.ch/host/ekatabahuddeshiysanstha.org/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-18 18:01:28 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Ekatabahuddeshiysanstha.org: generic_phishing campaign The domain ekatabahuddeshiysanstha.org is currently classified as a high‑risk generic_phishing operation and remains active as of July 18, 2026. Registration details show it was created on March 17, 2018 through PDR Ltd. d/b/a PublicDomainRegistry.com, and it uses Let's Encrypt (YR1) for TLS termination. The authoritative name servers are ns1.bh-24.webhostbox.net and ns2.bh-24.webhostbox.net, and DNS resolution points to IP address 204.11.59.88. Threat intelligence from AlienVault OTX indicates the domain appears in five separate pulses, and VirusTotal reports that 16 of 91 security‑vendor scanners have flagged it. No public analysis of the site’s content or payload has been released, so the exact lure or credential‑harvesting mechanism remains unknown. Defenders should add the domain and its resolved IP to block lists, monitor outbound traffic for connections to the host, and incorporate the domain into existing phishing detection rules. Continuous observation of any changes to the DNS records, certificate renewal, or additional VirusTotal detections is advised to maintain situational awareness. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260718-AD9395 TLS cert SHA-256: 24328fc058080231d02501a2fbacff88494becefad500ede6623356d450b9926 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/ekatabahuddeshiysanstha.org/ JSON API: https://api.destroy.tools/v1/check?domain=ekatabahuddeshiysanstha.org Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 210,284 domains (97,379 alive under monitoring, 111,874 confirmed takedowns/dead). Site: https://phishdestroy.io