# PhishDestroy threat dossier — hiscocklimited.com.echodials.com ================================================================ Fetched: 2026-07-29 15:49:07 UTC Canonical: https://phishdestroy.io/domain/hiscocklimited.com.echodials.com/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 73/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 178.238.236.172 (FR, Lauterbourg) ASN: AS51167 Contabo GmbH Hosting org: Contabo GmbH Registrar: NameCheap, Inc. Nameservers: ["ns1.echodials.com", "ns2.echodials.com"] Page title: Ea & Ja Hiscock Limited | Dairy Farming & Livestock | Dorset HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-09-15 Status: INVALID chain Fingerprint: efe58512cd5a2e9fcde358d1b6838cff537d2cba0be6a7e00e6e7e605a37178a Subject Alternative Names (related infrastructure — often same operator): - hiscocklimited.com - www.hiscocklimited.com.echodials.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-26 12:43:08 UTC (by PhishDestroy tracker) Last verified: 2026-07-29 16:20:27 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-26 12:45:13 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] hiscocklimited.com.echodials.com Phishing Infrastructure Alert The domain hiscocklimited.com.echodials.com was observed serving HTTP content with a 200 OK response on July 26, 2026. It is hosted on the DNS zone managed by ns1.echodials.com and ns2.echodials.com, both controlled by the same provider that supplies the parent domain echodials.com. Registration details show the domain was registered through NameCheap, Inc., a registrar known for low‑cost bulk registrations. The domain currently resolves to an IP address that is not listed in the supplied data, and no additional hosting metadata is available. The site was submitted to VirusTotal and examined by 91 AV engines; none reported a detection at the time of scanning, which does not guarantee the absence of malicious payloads. Independent blocklist monitoring indicates the domain is present on a single security blocklist and has been flagged by the PhishDestroy feed, confirming that at least one industry‑wide anti‑phishing service considers the host malicious. No public SSL certificate details, Safe Browsing verdicts, OTX entries, or page‑title information were supplied, leaving the visual content and specific credential‑stealing tactics unverified. The combination of a newly registered domain, a generic sub‑domain structure, active HTTP service, and inclusion on a phishing‑specific blocklist suggests the infrastructure is being used for a phishing campaign, even though the exact target brand or lure cannot be confirmed from the available evidence. Defenders should treat the domain as hostile, block DNS resolution and HTTP requests at the network perimeter, add the host to local deny‑lists, and continue monitoring for any future sightings in URL filtering or email scanning solutions. Ongoing intelligence collection should focus on retrieving the page title, SSL certificate fingerprint, and any observed payloads to refine the risk assessment and support attribution. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: efe58512cd5a2e9fcde358d1b6838cff537d2cba0be6a7e00e6e7e605a37178a ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/hiscocklimited.com.echodials.com/ JSON API: https://api.destroy.tools/v1/check?domain=hiscocklimited.com.echodials.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,484 domains (83,251 alive under monitoring, 109,716 confirmed takedowns/dead). Site: https://phishdestroy.io