# PhishDestroy threat dossier — ftjzh.cc ================================================================ Fetched: 2026-07-26 05:58:18 UTC Canonical: https://phishdestroy.io/domain/ftjzh.cc/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Credential Phishing ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 7/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Chong Lua Dao, Forcepoint ThreatSeeker, Gridinsoft, Kaspersky, LevelBlue, SOCRadar AlienVault OTX: 3 pulses (threat-intel feed mentions) Public blocklists: listed on 3 independent blocklists Google Safe Browsing: FLAGGED ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 69.72.83.158 (HK, Cheung Sha Wan) ASN: AS45753 Netsec Limited Hosting org: Netsec Registrar: Gname.com Pte. Ltd. Nameservers: a.share-dns.com, a1.share-dns.com, b.share-dns.net, b1.share-dns.net Registered: 2025-10-28 Expires: 2026-10-28 Page title: COINVOYAGES HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-09-30 Status: INVALID chain Fingerprint: 6f41e53f6345e682f59b6cd7253433a76e67c4ae73fe882ec844d51aebe6cf54 Subject Alternative Names (related infrastructure — often same operator): - fljh.net - ftjhi.net - ftjhiz.com - ftjiht.com - www.fljh.net - www.ftjhi.net - www.ftjhiz.com - www.ftjiht.com - www.ftjzh.cc ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-10-28 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-17 17:30:28 UTC (by PhishDestroy tracker) First reported: 2026-07-17 15:32:43 UTC (abuse notice filed) Last verified: 2026-07-26 04:20:27 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f70b1-e3fa-73f3-91ad-20a7cf4b55e1/ URLQuery: https://urlquery.net/report/b2ca4b19-019a-4fbd-b558-29c5f0e15f23 Wayback Machine: https://web.archive.org/web/*/ftjzh.cc crt.sh CT logs: https://crt.sh/?q=%25.ftjzh.cc Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=ftjzh.cc AlienVault OTX: https://otx.alienvault.com/indicator/domain/ftjzh.cc URLhaus: https://urlhaus.abuse.ch/host/ftjzh.cc/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-17 17:40:43 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is ftjzh.cc a Fake Login Scam Site? Analysis indicates that ftjzh.cc is an active phishing domain registered on October 28, 2025, through Gname.com Pte. Ltd. The domain currently resolves to IP address 69.72.83.158 and uses nameservers a.share-dns.com, a1.share-dns.com, b.share-dns.net, and b1.share-dns.net. Google Safe Browsing has flagged this domain with a SOCIAL_ENGINEERING classification, confirming its involvement in deceptive practices designed to trick users into disclosing sensitive information. The infrastructure supporting ftjzh.cc relies on shared DNS providers commonly associated with low-cost or bulletproof hosting, which are frequently exploited by threat actors to maintain operational resilience. No specific brand impersonation or phishing kit details have been confirmed at this time, so the exact nature of the fraudulent content remains unanalyzed. Defenders should treat this domain as high-risk and consider blocking resolution at the network level or implementing browser-based warnings for users. Given its continued activity as of July 17, 2026, monitoring for additional indicators or shifts in hosting patterns is recommended. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260717-5569DA Favicon MD5: b226459a559caff66218577c3693d397 TLS cert SHA-256: 6f41e53f6345e682f59b6cd7253433a76e67c4ae73fe882ec844d51aebe6cf54 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/ftjzh.cc/ JSON API: https://api.destroy.tools/v1/check?domain=ftjzh.cc Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,604 domains (65,238 alive under monitoring, 128,816 confirmed takedowns/dead). Site: https://phishdestroy.io