# PhishDestroy threat dossier — elitestartlimited.com ================================================================ Fetched: 2026-07-28 21:33:53 UTC Canonical: https://phishdestroy.io/domain/elitestartlimited.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 12/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Lionic, Netcraft, Sophos Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.67.196.147 (US, San Francisco) ASN: ASAS13335 CLOUDFLARENET - Cloudflare, Inc., US Hosting org: AS13335 Cloudflare, Inc. Registrar: Hosting Concepts B.V. d/b/a Registrar.eu Nameservers: cora.ns.cloudflare.com, lennon.ns.cloudflare.com Registered: 2024-10-28 Expires: 2026-10-28 Page title: elitestartlimited.com HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-09-09 Status: INVALID chain Fingerprint: 474242fb27ade19b1401b18b1fb8d7e723079accf19e6cfb0ad15da57d5abd84 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2024-10-28 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 06:00:16 UTC (by PhishDestroy tracker) First reported: 2026-07-27 06:00:15 UTC (abuse notice filed) Last verified: 2026-07-28 21:04:07 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa1c0-4de1-75cd-8efb-76af0be50f0b/ URLQuery: https://urlquery.net/report/c65d86d5-bb6e-45f4-944e-aa4f5f91ebee Wayback Machine: https://web.archive.org/web/*/elitestartlimited.com crt.sh CT logs: https://crt.sh/?q=%25.elitestartlimited.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=elitestartlimited.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/elitestartlimited.com URLhaus: https://urlhaus.abuse.ch/host/elitestartlimited.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 06:01:27 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Elitestartlimited.com used for high‑risk generic phishing This domain, elitestartlimited.com, is currently active and has been observed resolving to the IP address 172.67.196.147. The domain was registered on October 28, 2024 through Hosting Concepts B.V. d/b/a Registrar.eu, and its authoritative name servers are cora.ns.cloudflare.com and lennon.ns.cloudflare.com, indicating that the hosting infrastructure is provided by Cloudflare. The domain appears on a single security blocklist and has been explicitly blocked by the PhishDestroy feed. VirusTotal analysis shows that twelve of ninety‑one scanning engines flagged the domain as malicious, confirming a consensus of moderate detection across commercial scanners. The risk level has been assessed as high, and the threat type is classified as generic phishing. Available evidence confirms that the domain’s DNS resolves consistently to the Cloudflare‑owned address, which is commonly leveraged for fast‑flux or proxy services. No additional intelligence such as Safe Browsing verdicts, OTX mentions, SSL certificate details, HTTP response codes, trust scores, page title, or content snapshots have been published, leaving the exact payload or credential‑harvesting mechanism unverified. The limited visibility of only one blocklist entry suggests that broader community awareness may still be developing. Defenders should proactively block connections to 172.67.196.147 and add elitestartlimited.com to local deny lists. Monitoring of the associated Cloudflare name servers for any changes, as well as periodic re‑scanning on VirusTotal or similar services, is recommended to capture potential shifts in the domain’s behavior. Email security gateways should enforce URL filtering for this domain, and endpoint protection solutions ought to flag any files or processes that reference the observed IP address. Continuous threat‑intel updates are advised to capture any future attribution or campaign expansion. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-0B561D Favicon MD5: 2290c6183c867073daa0ca30338a5f52 TLS cert SHA-256: 474242fb27ade19b1401b18b1fb8d7e723079accf19e6cfb0ad15da57d5abd84 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/elitestartlimited.com/ JSON API: https://api.destroy.tools/v1/check?domain=elitestartlimited.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 208,135 domains (82,977 alive under monitoring, 124,126 confirmed takedowns/dead). Site: https://phishdestroy.io