# PhishDestroy threat dossier — helpcloud-location-map.com ================================================================ Fetched: 2026-05-24 08:11:58 UTC Canonical: https://phishdestroy.io/domain/helpcloud-location-map.com/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users (type: status_split) (score: 1/6) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 9/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, CRDF, Fortinet, G-Data, LevelBlue, SOCRadar, Sophos, Webroot Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 161.97.140.80 (FR, Lauterbourg) ASN: AS51167 Contabo GmbH Hosting org: Contabo GmbH Registrar: Sav.com, LLC Nameservers: ns1.tacomovilserver.us, ns2.tacomovilserver.us Registered: 2026-04-22 Page title: No Internet HTTP response: 200 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-22 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-23 17:25:44 UTC (by PhishDestroy tracker) Last verified: 2026-05-23 21:25:29 UTC Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e5539-8ccf-72d1-ae62-7f382513848a/ Wayback Machine: https://web.archive.org/web/*/helpcloud-location-map.com crt.sh CT logs: https://crt.sh/?q=%25.helpcloud-location-map.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=helpcloud-location-map.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/helpcloud-location-map.com URLhaus: https://urlhaus.abuse.ch/host/helpcloud-location-map.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-23 17:26:45 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies helpcloud-location-map.com as an active generic phishing domain (seed 02fbdc) distributing fraudulent web pages under the guise of a legitimate service. The threat actor behind this campaign employs social engineering tactics to deceive users into revealing sensitive information, such as login credentials or financial details. The page title 'No Internet' suggests an attempt to mimic system errors, a common tactic to lower user suspicion and prompt interaction with malicious payloads. No specific brand or drainer kit has been directly associated with this domain in current intelligence, but its behavior aligns with credential harvesting operations typical of generic phishing campaigns. This domain exhibits multiple malicious indicators. PhishDestroy analysis confirms it has a VirusTotal detection score of 9/95 security vendors as of the investigation timestamp. Registered through Sav.com, LLC, the domain resolves to IP 161.97.140.80 and was created on April 22, 2026. It holds an SSL certificate issued by Let's Encrypt, adding a false sense of legitimacy. The domain appears on one security blocklist and is specifically flagged and blocked by OpenPhish, a reputable threat intelligence feed. Current forensic data does not indicate inclusion in Google Safe Browsing (GSB) blocklists. The campaign remains ACTIVE as of the latest assessment, with no evidence of takedown or mitigation by the registrar or hosting provider. Blocking actions are currently limited to OpenPhish and one additional blocklist, leaving exposure to users who rely on default or unpatched security configurations. The elevated risk stems from the domain's recent creation, active infrastructure, and partial evasion of detection mechanisms. Immediate actions for users include blocking the domain at DNS or firewall levels, avoiding any interaction with suspicious pages, and reporting observed activity to relevant threat intelligence platforms. The remaining risk is elevated due to the domain’s active status, lack of widespread blocklisting, and the potential for rapid propagation through phishing distribution networks. Continuous monitoring is advised as this campaign may escalate or shift infrastructure. ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/helpcloud-location-map.com/ JSON API: https://api.destroy.tools/v1/check?domain=helpcloud-location-map.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 152,979 domains (39,994 alive under monitoring, 112,610 confirmed takedowns/dead). Site: https://phishdestroy.io