# PhishDestroy threat dossier — formapply-verifiedbadge-now.surge.sh ================================================================ Fetched: 2026-07-31 07:30:16 UTC Canonical: https://phishdestroy.io/domain/formapply-verifiedbadge-now.surge.sh/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 63/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 16/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Kaspersky, Lionic, MalwareURL, Sophos, VIPRE, Webroot Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 159.203.159.100 (US, North Bergen) ASN: AS14061 DigitalOcean, LLC Hosting org: Digital Ocean Registrar: Surge.sh Nameservers: NS_NOT_FOUND Registered: 2026-05-21 Page title: project not found HTTP response: 404 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-21 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-29 11:02:36 UTC (by PhishDestroy tracker) Last verified: 2026-07-31 08:20:20 UTC Neutralised: 2026-06-06 17:30:11 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e48df-a7de-77c4-a89a-9800d236a504/ Wayback Machine: https://web.archive.org/web/*/formapply-verifiedbadge-now.surge.sh crt.sh CT logs: https://crt.sh/?q=%25.formapply-verifiedbadge-now.surge.sh Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=formapply-verifiedbadge-now.surge.sh AlienVault OTX: https://otx.alienvault.com/indicator/domain/formapply-verifiedbadge-now.surge.sh URLhaus: https://urlhaus.abuse.ch/host/formapply-verifiedbadge-now.surge.sh/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-29 11:03:56 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] formapply-verifiedbadge-now.surge.sh: Confirmed Phishing Site On July 29, 2026 the domain formapply-verifiedbadge-now.surge.sh was observed hosting a generic phishing campaign. The domain was registered through the free‑hosting provider Surge.sh and resolves to the IPv4 address 159.203.159.100. No authoritative nameserver records are returned (NS_NOT_FOUND), which is typical for dynamically assigned hosting on the Surge platform. The site is currently listed as active with an elevated risk rating. Multiple defensive feeds have flagged the domain. PhishDestroy has added it to its blocklist, and it appears on one additional security blocklist. VirusTotal analysis shows that 16 of 91 scanning engines returned a malicious classification, reinforcing the suspicion of phishing use. No public Safe Browsing, Open Threat Exchange, or SSL certificate details were available at the time of analysis, and the HTTP response code could not be retrieved. The page title and any brand targeting have not been disclosed, so the specific lure employed by the site cannot be confirmed. Given the combination of registrar‑level abuse, malicious detection scores, and blocklist presence, defenders should treat any traffic to formapply-verifiedbadge-now.surge.sh as hostile. Network sensors should block DNS resolution and HTTP/S connections to the domain, and endpoint solutions should quarantine any files or URLs associated with it. Continuous monitoring of the IP address 159.203.159.100 is recommended, as the host may be reused for additional malicious campaigns. Organizations should also update threat intelligence feeds to include this indicator to mitigate future exposure. ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/formapply-verifiedbadge-now.surge.sh/ JSON API: https://api.destroy.tools/v1/check?domain=formapply-verifiedbadge-now.surge.sh Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 196,239 domains (84,225 alive under monitoring, 27,268 confirmed neutralized). Site: https://phishdestroy.io