# PhishDestroy threat dossier — gir.marsbahis.com ================================================================ Fetched: 2026-07-29 17:52:41 UTC Canonical: https://phishdestroy.io/domain/gir.marsbahis.com/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 73/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- Registrar: Tucows Domains Inc. Nameservers: ["ns-1499.awsdns-59.org", "ns-1540.awsdns-00.co.uk", "ns-518.awsdns-00.net", "ns-78.awsdns-09.com"] HTTP response: 301 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-26 08:23:08 UTC (by PhishDestroy tracker) Last verified: 2026-07-29 16:20:28 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-26 08:24:33 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is gir.marsbahis.com a phishing site? The subdomain gir.marsbahis.com is currently listed as active and under investigation for generic phishing. Registration data shows the domain was obtained through Tucows Domains Inc., and its authoritative name servers are ns-1499.awsdns-59.org, ns-1540.awsdns-00.co.uk, ns-518.awsdns-00.net, and a fourth entry truncated in the source. An HTTP request to the domain yields a 301 redirect response, indicating that the site forwards traffic but no page content has been captured in the available data. The domain appears on one external security blocklist and is explicitly blocked by the PhishDestroy filtering service. VirusTotal records indicate that 91 scanning engines have examined the domain, with none reporting a detection at the time of analysis; this lack of detections is not evidence of benign intent. No information is available regarding SSL/TLS certificates, hosting IP address, geographic location, or page title, and Safe Browsing or OTX entries are not present in the current intelligence set. Given the combination of registrar details, redirect behavior, blocklist presence, and the active phishing classification, defenders should treat gir.marsbahis.com as potentially malicious. Recommended actions include adding the domain to DNS and URL filtering policies, monitoring DNS query volumes for anomalous spikes, and gathering additional telemetry such as TLS handshake data and final redirect targets to refine risk assessments as further evidence becomes available. ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/gir.marsbahis.com/ JSON API: https://api.destroy.tools/v1/check?domain=gir.marsbahis.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,499 domains (83,266 alive under monitoring, 109,716 confirmed takedowns/dead). Site: https://phishdestroy.io