# PhishDestroy threat dossier — fa219.com ================================================================ Fetched: 2026-07-26 19:26:39 UTC Canonical: https://phishdestroy.io/domain/fa219.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Credential Phishing Targeted brand: Microsoft ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 3/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Kaspersky, SOCRadar Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 150.171.28.10 (US, New York City) ASN: ASAS8075 MICROSOFT-CORP-MSN-AS-BLOCK - Microsoft Corporation, US Hosting org: AS19318 Interserver, Inc Registrar: Name SRS AB Nameservers: a.share-dns.com, a4.share-dns.com, b.share-dns.net, b4.share-dns.net Registered: 2025-07-22 Expires: 2026-07-22 Page title: Microsoft HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE2 Expires: 2026-09-23 Status: INVALID chain Fingerprint: b01ab9784496f7aceddbc3745f1f644baaf4794b45abcf1fc36f379782266a27 Subject Alternative Names (related infrastructure — often same operator): - www.fa219.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-07-22 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-08 20:53:21 UTC (by PhishDestroy tracker) Last verified: 2026-07-26 20:20:28 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f4312-f2d2-7431-9e4a-de3ede84309a/ Wayback Machine: https://web.archive.org/web/*/fa219.com crt.sh CT logs: https://crt.sh/?q=%25.fa219.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=fa219.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/fa219.com URLhaus: https://urlhaus.abuse.ch/host/fa219.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-08 20:54:44 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is fa219.com a Credential Theft Scam Targeting Streaming Users? This domain is flagged as a high-risk credential theft operation targeting users of streaming platforms. Analysis indicates the site employs deceptive tactics to harvest login credentials, likely through fake login portals or account verification prompts. The page title, translated from Chinese as "Strawberry Player," suggests an attempt to impersonate legitimate media streaming services, a common vector for credential theft schemes. Infrastructure analysis reveals multiple concerning indicators. The domain fa219.com was registered on July 22, 2025, through Name SRS AB, a registrar frequently associated with newly created high-risk domains. It resolves to the IP address 162.246.20.155, which has been linked to other malicious activities in recent threat intelligence reports. VirusTotal detection shows 2 out of 95 security vendors have flagged this domain, a low but non-negligible signal given the domain's recent creation. The SSL certificate is issued by Let's Encrypt, a common choice for both legitimate and malicious sites due to its free and automated nature. No major blocklists or trust scores currently list this domain, but its active status and recent registration amplify the risk. Mitigation steps for credential theft threats include immediate avoidance of the domain and any associated links. Users who may have interacted with the site should reset passwords for streaming services and any accounts where credentials were reused, prioritizing those with financial or personal data. Enable multi-factor authentication (MFA) on all critical accounts to mitigate unauthorized access. Organizations should block the domain and IP at the network level and monitor for signs of credential misuse. Security teams are advised to analyze network logs for connections to 162.246.20.155 and review endpoint telemetry for indicators of compromise related to this infrastructure. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: b01ab9784496f7aceddbc3745f1f644baaf4794b45abcf1fc36f379782266a27 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/fa219.com/ JSON API: https://api.destroy.tools/v1/check?domain=fa219.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 199,312 domains (68,604 alive under monitoring, 129,159 confirmed takedowns/dead). Site: https://phishdestroy.io