# PhishDestroy threat dossier — emctheatre.com ================================================================ Fetched: 2026-07-25 10:33:32 UTC Canonical: https://phishdestroy.io/domain/emctheatre.com/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 10/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Cluster25, CRDF, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, MalwareURL, SOCRadar, Sophos AlienVault OTX: 3 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 216.222.200.253 (US, Los Angeles) ASN: AS40092 HostPapa Hosting org: HostPapa Registrar: Tucows Domains Inc. Nameservers: ["ns2011.websiteservername.com", "ns2012.websiteservername.com"] Page title: EMC Theatre site – Eagle Mountain Community Theatre HTTP response: 500 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-09-07 Status: INVALID chain Fingerprint: ff36bca820dca96d0e938286ff234c5fbc0f789428353be90db8acdfef32e421 Subject Alternative Names (related infrastructure — often same operator): - emctheater.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-19 12:38:21 UTC (by PhishDestroy tracker) Last verified: 2026-07-25 12:20:32 UTC Neutralised: 2026-07-23 12:22:27 UTC Current status: taken down (registrar suspended or DNS dead) ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-20 00:17:34 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is emctheatre.com a Generic Phishing Threat? Analysis of emctheatre.com reveals significant threat indicators, categorizing it as a high-risk generic phishing domain. The domain has been identified in three threat intelligence pulses within the AlienVault OTX system, emphasizing its malicious potential. Currently registered through Tucows Domains Inc., the site resolves to an IP address located in the US (216.222.200.253), and is served by HostPapa. HTTP status checks indicate the site is active with a status of 200. However, security assessments flag the domain as being present on one security blocklist, specifically blocked by PhishDestroy, indicating known phishing activities. Furthermore, scans from VirusTotal show that 10 out of 91 security vendors have raised concerns regarding this domain. The presence of a Let's Encrypt SSL certificate does not mitigate the risk, as it has been utilized by phishing domains in the past. The nameservers listed for the domain raise further suspicion, as they are commonly associated with less reputable hosting services. Defenders should exercise caution and consider blocking or monitoring traffic to this domain, as its association with high-risk phishing activities poses a potential cybersecurity threat. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: ff36bca820dca96d0e938286ff234c5fbc0f789428353be90db8acdfef32e421 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/emctheatre.com/ JSON API: https://api.destroy.tools/v1/check?domain=emctheatre.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 189,889 domains (60,107 alive under monitoring, 128,223 confirmed takedowns/dead). Site: https://phishdestroy.io