# PhishDestroy threat dossier — hfltwy.com ================================================================ Fetched: 2026-07-26 14:48:57 UTC Canonical: https://phishdestroy.io/domain/hfltwy.com/ ## VERDICT ---------------------------------------------------------------- ACTIVE THREAT — multiple warning signs Composite threat score: 55/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- Registrar: Gname.com Pte. Ltd. Nameservers: ["ns1.fbi.seized.gov", "ns2.fbi.seized.gov"] HTTP response: 200 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-26 13:33:09 UTC (by PhishDestroy tracker) Last verified: 2026-07-26 16:31:14 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-26 13:34:14 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] hfltwy.com Safety Check — Generic Phishing Detected Analysis of hfltwy.com on 2026-07-26 confirms the domain is currently active and serving HTTP content with a 200 response code. The authoritative name servers resolve to ns1.fbi.seized.gov and ns2.fbi.seized.gov, which are atypical and may indicate compromised infrastructure. The domain is listed on a single security blocklist and has been explicitly blocked by the PhishDestroy filtering service. VirusTotal records show that the site was examined by 91 antivirus and URL-reputation engines; none of the engines raised a detection at the time of scanning. Registration data identifies Gname.com Pte. Ltd. as the registrar, but no further registrant details are disclosed. No public information regarding the hosting IP address, ASN, geographic location, SSL certificate details, or page title has been released, leaving those vectors unverified. The available evidence points to a generic phishing operation, consistent with the threat type designation, although the specific lure or targeted brand has not been disclosed. Because the domain returns a valid HTTP page and is already being filtered by at least one commercial phishing-blocking product, it should be added to local denial-of-service and URL-filtering policies. Continuous monitoring of DNS resolution, blocklist status, and any future VirusTotal scans is recommended to detect changes in malicious behavior. Organizations should also consider sink-holing or redirecting traffic to a safe-browse warning page to mitigate end-user exposure while further forensic analysis is performed. ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/hfltwy.com/ JSON API: https://api.destroy.tools/v1/check?domain=hfltwy.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 198,198 domains (67,517 alive under monitoring, 129,132 confirmed takedowns/dead). Site: https://phishdestroy.io