# PhishDestroy threat dossier — financialtradinglimited.com.ciphercorporatelimited.com ================================================================ Fetched: 2026-07-29 05:04:19 UTC Canonical: https://phishdestroy.io/domain/financialtradinglimited.com.ciphercorporatelimited.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 83/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/91 security vendors flagged this domain Flagging vendors: CRDF, SOCRadar Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 198.251.84.200 (LU, Luxembourg) ASN: AS53667 FranTech Solutions Hosting org: FranTech Solutions Registrar: Global Domain Group LLC Nameservers: ["ns5.my-control-panel.com", "ns6.my-control-panel.com"] HTTP response: 302 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-27 05:23:09 UTC (by PhishDestroy tracker) Last verified: 2026-07-29 04:20:30 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 05:26:07 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] financialtradinglimited.com.ciphercor – Generic Phishing The domain financialtradinglimited.com.ciphercorporatelimited.com was observed issuing an HTTP 302 redirect response. It appears on a single security blocklist and has been manually blocked by the PhishDestroy mitigation service, indicating that threat‑intelligence providers have identified it as malicious. Registration data shows the name was created through Global Domain Group LLC, and the authoritative name servers are ns5.my‑control‑panel.com and ns6.my‑control‑panel.com. VirusTotal analysis reports that two out of ninety‑one scanning engines flagged the domain, providing a modest detection signal. Infrastructure details beyond the registrar and nameservers are not publicly disclosed; no SSL certificate information, IP address, or page title has been released, so a complete profile of the hosting environment cannot be assembled at this time. The limited blocklist presence suggests that only a few repositories have yet recorded the domain, which may reduce early warning for some networks. Nonetheless, the 302 redirect behavior is typical of phishing infrastructure that forwards victims to a secondary landing page or credential‑harvesting site, even though the final destination URL is not captured in the current dataset. Defenders should add the domain to local DNS deny lists and enforce URL‑filtering policies that block any HTTP request to it. Monitoring outbound traffic for unexpected 302 redirects to this name can reveal potential compromise attempts. Security teams are advised to re‑scan the domain with multi‑engine services regularly, as detection rates may increase if the phishing campaign expands. Email gateways should treat any message containing this domain as malicious, given its classification as a high‑risk generic phishing vector. Where possible, analysts should capture the resolved IP address once available, inspect TLS handshake logs for anomalous certificates, and consider sink‑hole routing for the IP to disrupt future victim access. ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/financialtradinglimited.com.ciphercorporatelimited.com/ JSON API: https://api.destroy.tools/v1/check?domain=financialtradinglimited.com.ciphercorporatelimited.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 192,492 domains (82,918 alive under monitoring, 107,787 confirmed takedowns/dead). Site: https://phishdestroy.io