# PhishDestroy threat dossier — elitedigitalplatform.com ================================================================ Fetched: 2026-07-27 12:44:02 UTC Canonical: https://phishdestroy.io/domain/elitedigitalplatform.com/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 66/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 10/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET, G-Data, Gridinsoft, Lionic, Netcraft AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 86.107.77.15 (DE, Eschborn) ASN: AS216395 HostBet Cloud Technologies Private Limited Hosting org: HostBet Cloud Technologies Private Limited Registrar: Dynadot Inc Nameservers: ns21.netlightsystems.com, ns22.netlightsystems.com Registered: 2026-03-13 Expires: 2027-03-13 Page title: elitedigitalplatform - Best Trading Platform HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-10-11 Status: INVALID chain Fingerprint: bf09c8075af62d6335504af0e8d46ddaea890b83cd08fe33442c3d193a5e08b8 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-03-13 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 06:04:38 UTC (by PhishDestroy tracker) First reported: 2026-07-27 05:51:01 UTC (abuse notice filed) Last verified: 2026-07-27 12:57:54 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa1c3-d752-77ff-9806-137715ab793b/ URLQuery: https://urlquery.net/report/28c71963-9d01-4782-9705-85b5b28a9ae0 Wayback Machine: https://web.archive.org/web/*/elitedigitalplatform.com crt.sh CT logs: https://crt.sh/?q=%25.elitedigitalplatform.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=elitedigitalplatform.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/elitedigitalplatform.com URLhaus: https://urlhaus.abuse.ch/host/elitedigitalplatform.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 06:09:28 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is elitedigitalplatform.com a Phishing Site? Analysis of elitedigitalplatform.com shows a high‑risk generic phishing infrastructure that remains active as of the report date, July 27, 2026. The domain was registered through Dynadot Inc on March 13, 2026 and resolves to the IPv4 address 86.107.77.15. Its authoritative nameservers are ns21.netlightsystems.com and ns22.netlightsystems.com, indicating that the hosting environment is provided by Netlight Systems. The domain appears on one public security blocklist and is actively blocked by the PhishDestroy service, reinforcing its malicious reputation. VirusTotal has recorded detections from ten of ninety‑one scanned security vendors, providing independent confirmation of malicious activity. No additional public intelligence such as Google Safe Browsing, OTX, or SSL/TLS details is currently available, and the page title or content has not been captured in the supplied data. Defenders should treat any communications referencing elitedigitalplatform.com as suspicious and block network traffic to both the domain and its resolved IP address. Email security gateways should add the domain to deny lists and enable URL filtering rules that reference the known blocklist entry. Continuous monitoring of the IP 86.107.77.15 for new host‑level indicators is advised, as the same server may host additional phishing campaigns. Because the registrar information is public, a takedown request to Dynadot Inc may be pursued, though the domain’s recent creation date suggests a fast‑flux or disposable‑domain strategy that could be replicated by the adversary. Until further forensic details such as page content or SSL certificates become available, the safest posture is to assume the domain is being used for credential‑harvesting attempts and to enforce strict user awareness controls around unsolicited requests that reference the domain. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-98EB77 Favicon MD5: 728265657ecb039ba498c7a61e9f6f0f TLS cert SHA-256: bf09c8075af62d6335504af0e8d46ddaea890b83cd08fe33442c3d193a5e08b8 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/elitedigitalplatform.com/ JSON API: https://api.destroy.tools/v1/check?domain=elitedigitalplatform.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 205,230 domains (80,402 alive under monitoring, 123,797 confirmed takedowns/dead). Site: https://phishdestroy.io