# PhishDestroy threat dossier — hex.arhamsoft.info ================================================================ Fetched: 2026-07-29 22:23:41 UTC Canonical: https://phishdestroy.io/domain/hex.arhamsoft.info/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 12/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, ESET, Forcepoint ThreatSeeker, Fortinet, Google Safe Browsing, Gridinsoft, Kaspersky, Lionic, Sophos, VIPRE, Webroot Public blocklists: listed on 1 independent blocklist Google Safe Browsing: FLAGGED ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 70.32.23.39 (US, Detroit) ASN: AS55293 A2 Hosting, Inc. Hosting org: A2 Hosting, Inc. Registrar: GoDaddy.com, LLC Nameservers: ["ns67.domaincontrol.com", "ns68.domaincontrol.com"] HTTP response: 403 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-10-21 Status: INVALID chain Fingerprint: f15e6a6975c9665a191b0d0886b17cd935bf1f71d956c89c6988420029d78e23 Subject Alternative Names (related infrastructure — often same operator): - wwwmi3-sr21.supercp.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-26 13:33:08 UTC (by PhishDestroy tracker) Last verified: 2026-07-30 00:17:46 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-26 13:34:58 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is hex.arhamsoft.info a Social Engineering Phishing Site? Analysis of hex.arhamsoft.info indicates this domain is actively engaged in social engineering phishing activity as of July 26, 2026. The domain is flagged by Google Safe Browsing for social engineering, a classification that typically involves deceptive tactics to trick users into divulging sensitive information. Infrastructure analysis reveals the domain is registered through GoDaddy.com, LLC, with nameservers ns67.domaincontrol.com and ns68.domaincontrol.com, and remains in an active status. It appears on one security blocklist and is blocked by PhishDestroy, further corroborating its malicious classification. VirusTotal reports 12 of 91 security vendors flagging the domain, providing additional detection context, though the specific nature of the phishing content remains unconfirmed due to a 403 HTTP status, which restricts direct access for further analysis. Defenders should treat this domain as high-risk based on the available indicators. The combination of Google Safe Browsing’s social engineering flag, blocklist presence, and vendor detections on VirusTotal provides sufficient evidence to warrant immediate blocking at the network perimeter. The domain’s registration details do not reveal additional anomalous patterns, but the active status and consistent detection across multiple sources suggest it is part of an ongoing campaign. No brand or specific phishing kit has been identified in the available data, so the exact target or lure remains uncertain. Organizations should monitor for connections to this domain in proxy logs, DNS queries, or endpoint telemetry and investigate any associated activity as potentially malicious. If internal access attempts are detected, users should be isolated for follow-up to assess potential credential exposure or malware delivery. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: f15e6a6975c9665a191b0d0886b17cd935bf1f71d956c89c6988420029d78e23 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/hex.arhamsoft.info/ JSON API: https://api.destroy.tools/v1/check?domain=hex.arhamsoft.info Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,509 domains (82,972 alive under monitoring, 110,024 confirmed takedowns/dead). Site: https://phishdestroy.io