# PhishDestroy threat dossier — ie.nhyfhbc.net ================================================================ Fetched: 2026-07-25 13:52:11 UTC Canonical: https://phishdestroy.io/domain/ie.nhyfhbc.net/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 71/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 10/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, Certego, Cluster25, CRDF, Fortinet, G-Data, Google Safebrowsing, Gridinsoft, SOCRadar, Webroot URLQuery: -1 detections Public blocklists: listed on 1 independent blocklist Google Safe Browsing: FLAGGED ## INFRASTRUCTURE ---------------------------------------------------------------- Registered: 2026-05-25 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-25 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-26 05:30:12 UTC (by PhishDestroy tracker) First reported: 2026-06-15 00:27:29 UTC (abuse notice filed) Last verified: 2026-07-25 12:20:48 UTC Neutralised: 2026-05-26 18:23:31 UTC Current status: taken down (registrar suspended or DNS dead) ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-24 10:20:51 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is ie.nhyfhbc.net a Phishing Site? Analysis of the domain ie.nhyfhbc.net indicates that it was registered on 25 May 2026 and is currently taken offline. The domain is classified as a generic phishing site and has been flagged by multiple security services. PhishDestroy has actively blocked the domain, and it appears on one external security blocklist. Google Safe Browsing lists the domain under social engineering, confirming its use in credential‑harvesting or credential‑stealing campaigns. VirusTotal reports that ten of ninety‑one scanned security vendors have generated detections for the domain, providing independent corroboration of malicious intent. The Gridinsoft trust score is 0 out of 100, reflecting a complete lack of trust. No additional infrastructure details such as hosting IP address, autonomous system number, or SSL certificate information have been observed in the available intelligence, and the page title or content has not been disclosed. Consequently, the full scope of the phishing infrastructure, including any associated command‑and‑control servers or drop sites, remains unknown. Defenders should ensure that the domain is added to local and network‑level deny lists, confirm that any existing firewall or proxy rules block traffic to and from ie.nhyfhbc.net, and monitor passive DNS feeds for re‑registration attempts. Because the domain is offline, immediate active mitigation is not required, but continuous observation is advised to detect potential revival or reuse of the same naming pattern. Integration of the observed detection counts and blocklist entries into threat‑intel platforms will improve early warning for related campaigns. ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/ie.nhyfhbc.net/ JSON API: https://api.destroy.tools/v1/check?domain=ie.nhyfhbc.net Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 190,833 domains (61,019 alive under monitoring, 128,255 confirmed takedowns/dead). Site: https://phishdestroy.io