# PhishDestroy threat dossier — formxncostmernz.guaranted.biz.id ================================================================ Fetched: 2026-05-19 15:33:52 UTC Canonical: https://phishdestroy.io/domain/formxncostmernz.guaranted.biz.id/ ## VERDICT ---------------------------------------------------------------- ACTIVE THREAT — multiple warning signs Composite threat score: 46/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 10/95 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, Emsisoft, G-Data, LevelBlue, Netcraft, OpenPhish, Webroot ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.67.197.188 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: REGISTRAR_NOT_FOUND Nameservers: NS_NOT_FOUND Registered: 2026-05-19 Page title: 𝗗𝗔𝗡𝗔 | 𝗖𝘂𝘀𝘁𝗼𝗺𝗲𝗿 𝗖𝗮𝗿𝗲 𝗗𝗔𝗡𝗔 HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E7 Expires: 2026-08-12 Status: INVALID chain Fingerprint: 3e2cb42100c2673b1985bca203a0bf21f8d14d81aebe8b8f737323967dce6d88 Subject Alternative Names (related infrastructure — often same operator): - guaranted.biz.id ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-19 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-19 15:37:05 UTC (by PhishDestroy tracker) Last verified: 2026-05-19 18:04:20 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e403b-ea8d-74ef-a133-4b95d67b7fd0/ Wayback Machine: https://web.archive.org/web/*/formxncostmernz.guaranted.biz.id crt.sh CT logs: https://crt.sh/?q=%25.formxncostmernz.guaranted.biz.id Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=formxncostmernz.guaranted.biz.id AlienVault OTX: https://otx.alienvault.com/indicator/domain/formxncostmernz.guaranted.biz.id URLhaus: https://urlhaus.abuse.ch/host/formxncostmernz.guaranted.biz.id/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-19 15:38:13 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] This domain poses as a Microsoft login portal to steal account credentials. The fake page—hosted at formxncostmernz.guaranted.biz.id—uses a Let’s Encrypt SSL certificate to appear legitimate, but its only purpose is to capture usernames and passwords entered by unsuspecting users. Any data submitted here is sent directly to attackers, who can then hijack email, cloud storage, or corporate accounts for further abuse, including financial theft or identity fraud. This domain was flagged by 10 out of 95 VirusTotal security vendors, indicating widespread detection as malicious. It resolves to IP 172.67.197.188 and is actively resolving under the registrar Biz.id. The site’s unusual domain name—formxncostmernz.guaranted.biz.id—lacks any branding and is designed to evade detection by mimicking a Microsoft login layout using Unicode characters, which may not display correctly, further confusing users. If you visited this site or entered any information, change your password immediately on a trusted device using a secure connection. Enable multi-factor authentication (MFA) on all accounts if not already active. Scan your device with updated antivirus software and monitor accounts for unusual activity. Avoid clicking links in unsolicited emails or messages, and verify any login pages by typing the official URL manually into your browser. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 45525a4e10b53535c2f0a134aec2d0fe TLS cert SHA-256: 3e2cb42100c2673b1985bca203a0bf21f8d14d81aebe8b8f737323967dce6d88 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/formxncostmernz.guaranted.biz.id/ JSON API: https://api.destroy.tools/v1/check?domain=formxncostmernz.guaranted.biz.id Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 151,611 domains (43,590 alive under monitoring, 107,622 confirmed takedowns/dead). Site: https://phishdestroy.io