# PhishDestroy threat dossier — fingramota.kz ================================================================ Fetched: 2026-06-27 11:41:46 UTC Canonical: https://phishdestroy.io/domain/fingramota.kz/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 68/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/91 security vendors flagged this domain Flagging vendors: Forcepoint ThreatSeeker, Gridinsoft Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 185.129.95.47 (KZ, Almaty) ASN: ASAS200590 asnls NLS Kazakhstan LLC, KZ Hosting org: AS200590 NLS Kazakhstan LLC Registrar: HOSTER.KZ Nameservers: ns1.hoster.kz, ns2.hoster.kz, ns3.hoster.kz Registered: 2016-11-29 Page title: Новости ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: GoGetSSL / GoGetSSL RSA DV CA Expires: 2026-10-02 Status: INVALID chain Fingerprint: e58dbca46e3c3f1726c243a5d2f5af0e36a9a5747382488e6499a88c9ff79272 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2016-11-29 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-06-17 10:35:11 UTC (by PhishDestroy tracker) First reported: 2026-06-17 15:24:07 UTC (abuse notice filed) Last verified: 2026-06-27 13:17:28 UTC Neutralised: 2026-06-18 00:19:28 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019ed4b6-a9bf-709d-942a-ab0f94a46436/ URLQuery: https://urlquery.net/report/ac01927f-fcf1-4717-aefe-f0583d6c34f8 Wayback Machine: https://web.archive.org/web/*/fingramota.kz crt.sh CT logs: https://crt.sh/?q=%25.fingramota.kz Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=fingramota.kz AlienVault OTX: https://otx.alienvault.com/indicator/domain/fingramota.kz URLhaus: https://urlhaus.abuse.ch/host/fingramota.kz/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-18 16:35:18 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] The domain fingramota.kz has been identified as a generic phishing threat, masquerading as a platform for financial literacy improvement under the title "FinGramota.kz - Повышение финансовой грамотности населения." This domain was registered through HOSTER.KZ and resolves to the IP address 185.129.95.47, with a creation date of November 29, 2016. PhishDestroy's analysis reveals that while the domain appears legitimate at first glance, its true purpose is to deceive users into divulging sensitive information. Technical indicators further support the elevated risk level associated with fingramota.kz. VirusTotal reports that 2 out of 95 security vendors flag this domain as malicious, and it appears on 1 security blocklist. The SSL certificate is issued by GoGetSSL / GoGetSSL RSA DV CA, which is a legitimate certificate authority, but this does not preclude the domain from being used for phishing. The domain's long registration history (since 2016) may be an attempt to appear trustworthy, but the current activity suggests compromise or malicious intent. Currently, fingramota.kz is offline, which mitigates immediate risk. However, the domain could potentially be reactivated by threat actors. Users are advised to avoid any interaction with this domain and to report any attempts to access it. PhishDestroy recommends monitoring for similar domains and staying vigilant against financial-themed phishing campaigns. The remaining risk is low while offline, but constant vigilance is necessary as the domain's infrastructure could be repurposed. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260617-43AE13 Favicon MD5: 16f2fe79956b1e7f142a9b277e6b249b TLS cert SHA-256: e58dbca46e3c3f1726c243a5d2f5af0e36a9a5747382488e6499a88c9ff79272 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/fingramota.kz/ JSON API: https://api.destroy.tools/v1/check?domain=fingramota.kz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 170,827 domains (12,696 alive under monitoring, 157,726 confirmed takedowns/dead). Site: https://phishdestroy.io