# PhishDestroy threat dossier — incomecompoundinghub.com ================================================================ Fetched: 2026-07-02 23:40:01 UTC Canonical: https://phishdestroy.io/domain/incomecompoundinghub.com/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 74/100 (PhishDestroy scoring — see methodology below) Scam classification: Investment Scam Targeted brand: Compound ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/91 security vendors flagged this domain AlienVault OTX: 1 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 35.205.106.218 (BE, Brussels) ASN: ASAS396982 GOOGLE-CLOUD-PLATFORM - Google LLC, US Hosting org: AS396982 Google LLC Registrar: Fewmoretaps OU d/b/a Trustname.com !!! REGISTRAR INTEGRITY ALERT — Trustname / Fewmoretaps OU !!! Trustname (IANA #4318) is a shell company declaring EUR 120 annual revenue, 1 employee, negative equity, Belarusian ownership. Explicitly advertises itself as 'bulletproof' in its DNS TXT records. Primary source: https://phishdestroy.io/trustname-bulletproof-exposed Nameservers: ares.trustname.com, ns1.anycastdns.cz, ns2.anycastdns.cz, zeus.trustname.com Registered: 2026-06-27 Expires: 2027-06-27 Page title: Income compounding and wealth growth hub. ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-09-25 Status: INVALID chain Fingerprint: 5d56bb94a5810f7081ec546db50e8c0f54d45a1576493123c27c8039fd2b1ac6 Subject Alternative Names (related infrastructure — often same operator): - www.incomecompoundinghub.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-06-27 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-01 06:13:02 UTC (by PhishDestroy tracker) First reported: 2026-07-01 04:44:48 UTC (abuse notice filed) Last verified: 2026-07-03 00:20:37 UTC Neutralised: 2026-07-01 12:02:52 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f1be0-1d7f-762b-837c-2c3ba99cfdc9/ URLQuery: https://urlquery.net/report/1bc706aa-7915-4456-8c7c-76fed9adb490 Wayback Machine: https://web.archive.org/web/*/incomecompoundinghub.com crt.sh CT logs: https://crt.sh/?q=%25.incomecompoundinghub.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=incomecompoundinghub.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/incomecompoundinghub.com URLhaus: https://urlhaus.abuse.ch/host/incomecompoundinghub.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-01 06:16:13 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] This domain, incomecompoundinghub.com, is flagged for generic phishing activity targeting individuals seeking financial growth or investment opportunities. Analysis of the page title, 'Income compounding and wealth growth hub,' suggests an attempt to impersonate legitimate financial advisory or wealth management platforms. No specific brand association or drainer kit signatures have been identified at this stage, though the infrastructure aligns with known investment scam tactics designed to harvest credentials or financial details. Infrastructure analysis reveals the following technical indicators: the domain was registered on June 27, 2026, through Fewmoretaps OU d/b/a Trustname.com. It currently resolves to the IP address 35.205.106.218, with no detections on VirusTotal (0/95 engines). The SSL certificate is issued by Let's Encrypt, a common choice for both legitimate and malicious domains. Google Safe Browsing (GSB) has not flagged the domain at this time, and no blocklist entries have been recorded across public or private threat intelligence feeds. The domain remains active and operational, with no takedown or mitigation actions observed. Given the lack of detections and early-stage nature of the infrastructure, the risk of undetected exploitation persists. Users are advised to exercise caution when encountering this domain, particularly in contexts involving financial advice, investment opportunities, or wealth management. Network defenders should monitor for connections to 35.205.106.218 and consider blocking the domain at the perimeter until further intelligence is available. Continuous monitoring of related infrastructure is recommended to identify potential pivot points or additional malicious domains. [Updates since narrative was generated:] - Public blocklists: now listed on 1 feed - VirusTotal detections: now 2/91 (narrative was written when count was lower) ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260701-CF24EF Favicon MD5: c1fc5f83e8eea746265dbdca77264aa6 TLS cert SHA-256: 5d56bb94a5810f7081ec546db50e8c0f54d45a1576493123c27c8039fd2b1ac6 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/incomecompoundinghub.com/ JSON API: https://api.destroy.tools/v1/check?domain=incomecompoundinghub.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 174,015 domains (14,079 alive under monitoring, 159,195 confirmed takedowns/dead). Site: https://phishdestroy.io