# PhishDestroy threat dossier — forbit.icu ================================================================ Fetched: 2026-07-27 10:19:56 UTC Canonical: https://phishdestroy.io/domain/forbit.icu/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 78/100 (PhishDestroy scoring — see methodology below) Scam classification: Credential Phishing ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 12/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Lionic, Netcraft, Sophos, VIPRE AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 86.107.77.158 (DE, Eschborn) ASN: AS216395 HostBet Cloud Technologies Private Limited Hosting org: HostBet Cloud Technologies Private Limited Registrar: NAMECHEAP INC Nameservers: ns13.netlightsystems.com, ns14.netlightsystems.com Registered: 2025-07-30 Expires: 2026-07-30 Page title: Forbit|| Investment solutions designed with elegance and finesse ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-09-02 Status: INVALID chain Fingerprint: 5222166c7718df891269eb0df328e17b55136e8c1ef18504b5f40dd28d9ac798 Subject Alternative Names (related infrastructure — often same operator): - forbit.icu.emirateboost.shop - www.forbit.icu.emirateboost.shop ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-07-30 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 06:20:59 UTC (by PhishDestroy tracker) First reported: 2026-07-27 06:21:55 UTC (abuse notice filed) Last verified: 2026-07-27 09:02:48 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa1cc-d48f-7569-a9d1-d554cda31c2e/ URLQuery: https://urlquery.net/report/79426481-5bfc-4ad4-ba40-fd96d944a823 Wayback Machine: https://web.archive.org/web/*/forbit.icu crt.sh CT logs: https://crt.sh/?q=%25.forbit.icu Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=forbit.icu AlienVault OTX: https://otx.alienvault.com/indicator/domain/forbit.icu URLhaus: https://urlhaus.abuse.ch/host/forbit.icu/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 06:21:29 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] forbit.icu Credential Harvesting Alert Analysis indicates that the domain forbit.icu was registered on July 30, 2025 through Namecheap Inc. The authoritative nameservers are ns13.netlightsystems.com and ns14.netlightsystems.com, and the domain resolves to the IPv4 address 86.107.77.158. The domain appears on a single public blocklist and is actively listed by the PhishDestroy sinkhole, confirming that security‑focused services have identified it as malicious. VirusTotal has recorded detections from 12 of 91 scanning engines, reinforcing the suspicion that the site is being used for malicious purposes. The current WHOIS record does not disclose additional infrastructure such as an ASN or hosting provider beyond the IP address, and no SSL certificate information or HTTP response codes have been published. Publicly available page title, brand targeting, or phishing kit identifiers have not been released, leaving the exact impersonated service unspecified. Consequently, defenders cannot rely on content‑based signatures and must instead focus on network‑level indicators. Given the active status, defenders should add 86.107.77.158 to firewall deny lists and configure DNS filtering to block resolution of forbit.icu. Email gateways should be updated to flag any messages containing links to this domain, and endpoint protection solutions should incorporate the VirusTotal detection count as a heuristic for malicious activity. Continuous monitoring of the IP address for additional malicious payloads or command‑and‑control traffic is advised. Organizations that employ web‑proxy or secure web gateway solutions should ensure that requests to the domain are blocked, and any existing authentication attempts to the domain should be investigated for credential compromise. Because the site’s content has not been publicly analyzed, incident responders should treat any traffic to the domain as suspicious until further forensic evidence is obtained. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-07230A Favicon MD5: 4c66c991ad4aaef20e2c70e6b37dd299 TLS cert SHA-256: 5222166c7718df891269eb0df328e17b55136e8c1ef18504b5f40dd28d9ac798 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/forbit.icu/ JSON API: https://api.destroy.tools/v1/check?domain=forbit.icu Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 204,611 domains (79,953 alive under monitoring, 123,627 confirmed takedowns/dead). Site: https://phishdestroy.io