# PhishDestroy threat dossier — forge-shares.net ================================================================ Fetched: 2026-07-27 05:34:39 UTC Canonical: https://phishdestroy.io/domain/forge-shares.net/ ## VERDICT ---------------------------------------------------------------- ACTIVE THREAT — multiple warning signs Composite threat score: 49/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 4/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, CRDF, Gridinsoft, Netcraft Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 92.113.16.210 Registrar: HOSTINGER operations, UAB Nameservers: ns1.dns-parking.com, ns2.dns-parking.com Registered: 2024-08-16 Expires: 2026-08-16 Page title: forge-shares.net | The Better Way to Trade ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2024-08-16 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 06:14:44 UTC (by PhishDestroy tracker) Last verified: 2026-07-27 06:50:18 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa1c6-28f8-770d-b08c-11dcfff4742d/ Wayback Machine: https://web.archive.org/web/*/forge-shares.net crt.sh CT logs: https://crt.sh/?q=%25.forge-shares.net Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=forge-shares.net AlienVault OTX: https://otx.alienvault.com/indicator/domain/forge-shares.net URLhaus: https://urlhaus.abuse.ch/host/forge-shares.net/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 06:19:18 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is forge-shares.net a phishing campaign? The domain forge-shares.net was created on August 16, 2024 and is currently registered through HOSTINGER operations, UAB. Its authoritative name servers are ns1.dns-parking.com and ns2.dns-parking.com, indicating that the domain is parked on a generic hosting service. DNS resolution points to the IP address 92.113.16.210, which is the sole host observed for this domain. Threat intelligence shows that forge-shares.net is listed on a single security blocklist and is actively blocked by the PhishDestroy feed, confirming that at least one reputable anti‑phishing service has identified malicious activity associated with the domain. VirusTotal analysis recorded detections from four out of ninety‑one scanned security vendors, providing independent corroboration of its malicious nature. The overall risk assessment is marked as high, and the domain remains active as of the report date, July 27, 2026. Defenders should treat any traffic to or from forge-shares.net as potentially malicious. Network controls ought to block outbound connections to the IP 92.113.16.210 and enforce DNS filtering that denies resolution of the domain. Email security gateways should add the domain to block lists and quarantine any messages containing links or references to forge-shares.net. Because the domain uses generic parking name servers and lacks a dedicated SSL certificate profile, it is unlikely to host legitimate services, further supporting a precautionary block. Continuous monitoring of the IP address and any associated autonomous system changes is advised, as threat actors may shift hosting. Finally, security teams should review logs for any historical interactions with the domain to identify possible compromised credentials or data exfiltration attempts. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 401d71c468a4039e15ee9c67ec9e44e2 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/forge-shares.net/ JSON API: https://api.destroy.tools/v1/check?domain=forge-shares.net Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 202,849 domains (78,271 alive under monitoring, 123,547 confirmed takedowns/dead). Site: https://phishdestroy.io