# PhishDestroy threat dossier — gov.uk-dwpme.icu ================================================================ Fetched: 2026-07-31 01:42:29 UTC Canonical: https://phishdestroy.io/domain/gov.uk-dwpme.icu/ ## VERDICT ---------------------------------------------------------------- ACTIVE THREAT — multiple warning signs Composite threat score: 52/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 6/91 security vendors flagged this domain Flagging vendors: Forcepoint ThreatSeeker, Fortinet, Gridinsoft, LevelBlue, SOCRadar, Webroot Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- Registrar: Aceville Pte. Ltd. Registered: 2026-06-12 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-06-12 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-29 06:08:06 UTC (by PhishDestroy tracker) Last verified: 2026-07-31 01:04:06 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-29 06:09:21 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] gov.uk-dwpme.icu — Phishing Campaign Report gov.uk-dwpme.icu was registered on 12 June 2026 through Aceville Pte. Ltd. The domain has been observed in a limited set of threat‑intel feeds; it appears on one security blocklist and is currently listed by the PhishDestroy sinkhole as malicious. VirusTotal analysis shows that six of ninety‑one scanning engines returned a positive detection, confirming that at least a subset of commercial scanners consider the domain to be malicious. The limited number of detections suggests the payload or hosting may be recent or configured to evade broader detection, but the presence of multiple independent detections indicates a non‑trivial threat. No additional data such as IP address, hosting ASN, SSL details, or page title have been released publicly, leaving the full infrastructure and landing page content unknown. Consequently, defenders cannot attribute the domain to a specific phishing kit or verify the exact victim‑targeting technique. The combination of recent creation, a privacy‑light registrar, inclusion on a known phishing blocklist, and multiple vendor detections warrants an elevated risk rating. Organizations should add the domain to their deny lists, enforce URL filtering for .icu TLDs that reference UK government services, and monitor outbound DNS queries for related resolution patterns. Continuous re‑scanning on VirusTotal and periodic checks of blocklist feeds are recommended to capture any changes in detection status. Until further forensic evidence is released, the domain should be treated as actively malicious and blocked at network perimeter and endpoint layers. ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/gov.uk-dwpme.icu/ JSON API: https://api.destroy.tools/v1/check?domain=gov.uk-dwpme.icu Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 196,184 domains (94,021 alive under monitoring, 26,846 confirmed neutralized). Site: https://phishdestroy.io