# PhishDestroy threat dossier — growshift.digital ================================================================ Fetched: 2026-07-22 02:16:11 UTC Canonical: https://phishdestroy.io/domain/growshift.digital/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 83/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain URLQuery: 2 detections Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 77.90.185.84 (DE, Augsburg) ASN: AS213790 Limited Network LTD Hosting org: Limited Network LTD Registrar: Dynadot Inc Nameservers: abby.ns.cloudflare.com, anuj.ns.cloudflare.com Registered: 2025-12-28 Expires: 2026-12-28 Page title: Новый руководитель инвестиционного направления сделал важное обращение к гражданам. HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE2 Expires: 2026-08-31 Status: INVALID chain Fingerprint: 9f09ade84abb4d8b054afc44cfaf697a18b73b9652913f7a0b6be582f9016069 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-12-28 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-20 15:07:43 UTC (by PhishDestroy tracker) First reported: 2026-07-20 13:10:14 UTC (abuse notice filed) Last verified: 2026-07-22 03:00:18 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f7fa2-f34d-7358-b5bc-95b19a4f7cf7/ URLQuery: https://urlquery.net/report/4659198b-56cd-48f5-ab3a-08657beaf274 Wayback Machine: https://web.archive.org/web/*/growshift.digital crt.sh CT logs: https://crt.sh/?q=%25.growshift.digital Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=growshift.digital AlienVault OTX: https://otx.alienvault.com/indicator/domain/growshift.digital URLhaus: https://urlhaus.abuse.ch/host/growshift.digital/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-20 15:08:30 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] growshift.digital Fake Business Growth Portal Alert Analysis of the domain growshift.digital indicates it is an active phishing infrastructure currently under investigation. Registered on December 28, 2025, through Dynadot Inc, the domain resolves to the IP address 77.90.185.84. Infrastructure analysis reveals the use of Cloudflare nameservers (abby.ns.cloudflare.com and anuj.ns.cloudflare.com), a common tactic to obscure hosting origins and evade initial detection. The domain appears on one security blocklist, specifically PhishDestroy, which suggests prior identification as malicious, though the exact nature of the threat remains unverified. No detections were recorded by the 95 vendors that scanned the domain on VirusTotal, though this absence does not confirm safety. The domain's content has not been fully analyzed, and no specific brand impersonation or scam category has been confirmed. Defenders should treat this domain as high-risk due to its presence on a security blocklist and the use of Cloudflare for nameserver obfuscation. Network-level blocking at the IP and domain level is recommended, alongside monitoring for connections to 77.90.185.84. Further investigation is required to determine the exact phishing methodology, target audience, or potential credential harvesting tactics employed by this infrastructure. Organizations should correlate logs for any interactions with growshift.digital and report additional indicators to threat intelligence platforms. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260720-FD10C4 TLS cert SHA-256: 9f09ade84abb4d8b054afc44cfaf697a18b73b9652913f7a0b6be582f9016069 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/growshift.digital/ JSON API: https://api.destroy.tools/v1/check?domain=growshift.digital Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 187,720 domains (57,297 alive under monitoring, 128,779 confirmed takedowns/dead). Site: https://phishdestroy.io