# PhishDestroy threat dossier — gainbundle.com ================================================================ Fetched: 2026-07-29 03:41:27 UTC Canonical: https://phishdestroy.io/domain/gainbundle.com/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 71/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Bitcoin ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 4/91 security vendors flagged this domain Flagging vendors: CRDF, Gridinsoft, Netcraft, SOCRadar Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 86.107.77.57 (DE, Eschborn) ASN: AS216395 HostBet Cloud Technologies Private Limited Hosting org: HostBet Cloud Technologies Private Limited Registrar: TuringSign Inc. d/b/a Cosmotown Nameservers: ns1.stablewebtech.com, ns2.stablewebtech.com Registered: 2026-03-27 Expires: 2027-03-27 Page title: gainbundle.com Investments | Unique Bitcoin Investment Operators HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R13 Expires: 2026-08-25 Status: INVALID chain Fingerprint: 5e2119c66f69c3a911d1bb150cf032cbd9f02250bf9e80019e16341f11a9f3c6 Subject Alternative Names (related infrastructure — often same operator): - gainbundle.com.evulus.org - www.gainbundle.com.evulus.org ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-03-27 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 06:17:49 UTC (by PhishDestroy tracker) First reported: 2026-07-27 06:25:13 UTC (abuse notice filed) Last verified: 2026-07-29 04:24:22 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa2ad-517f-75ee-a4c5-630fd5953d97/ URLQuery: https://urlquery.net/report/123285b9-fe3e-42be-8350-215689f83975 Wayback Machine: https://web.archive.org/web/*/gainbundle.com crt.sh CT logs: https://crt.sh/?q=%25.gainbundle.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=gainbundle.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/gainbundle.com URLhaus: https://urlhaus.abuse.ch/host/gainbundle.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 06:19:09 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] gainbundle.com — Phishing Investigation Report The domain gainbundle.com was registered on March 27, 2026 through TuringSign Inc. doing business as Cosmotown. The authoritative name servers are ns1.stablewebtech.com and ns2.stablewebtech.com, and DNS resolution points to the IPv4 address 86.107.77.57. The address is currently listed on a single public security blocklist and the domain is still active as of the report date, July 27, 2026. VirusTotal scans show that three out of ninety‑one scanning engines have flagged the domain, indicating a non‑trivial level of malicious suspicion. Independent phishing‑monitoring services have already added gainbundle.com to their blocklists; for example, PhishDestroy reports the domain as blocked. The registration details, hosting infrastructure, and the modest detection count suggest that the domain is part of a newly‑operational phishing campaign rather than a long‑standing malicious site. No public information about the site’s page title, SSL certificate, HTTP response codes, or associated brand targets is available, so the exact phishing lure remains unknown. The limited visibility of the domain on blocklists and the low number of vendor detections may reflect either early stage deployment or evasion attempts. Defenders should treat gainbundle.com as a high‑risk indicator. Immediate actions include adding the domain and its resolved IP address 86.107.77.57 to network‑level deny lists, updating email security gateways to flag any messages containing the domain, and monitoring DNS queries for repeated resolution attempts. Continuous re‑scanning on VirusTotal and other multi‑engine platforms is recommended to capture any escalation in detection counts. Organizations that employ threat‑intel feeds should ensure that the domain is incorporated into their feed subscriptions, and SOC analysts should correlate any observed login attempts or credential submissions with this indicator to identify potential compromise attempts. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-6410A8 Favicon MD5: 6a7691cd9c1c428725ad614bb6d7e28e TLS cert SHA-256: 5e2119c66f69c3a911d1bb150cf032cbd9f02250bf9e80019e16341f11a9f3c6 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/gainbundle.com/ JSON API: https://api.destroy.tools/v1/check?domain=gainbundle.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 191,831 domains (82,883 alive under monitoring, 107,637 confirmed takedowns/dead). Site: https://phishdestroy.io