# PhishDestroy threat dossier — infinitecrown.club.gucert.xyz ================================================================ Fetched: 2026-07-27 08:31:23 UTC Canonical: https://phishdestroy.io/domain/infinitecrown.club.gucert.xyz/ ## VERDICT ---------------------------------------------------------------- ACTIVE THREAT — multiple warning signs Composite threat score: 55/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 9/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, Forcepoint ThreatSeeker, G-Data, Kaspersky, Netcraft, Sophos Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 162.245.237.212 (US, Tukwila) ASN: AS27323 Wowrack.com Hosting org: CENTRIOHOST-LLC Registrar: OwnRegistrar, Inc. Nameservers: dns1.webproserver.com, dns2.webproserver.com Registered: 2026-03-10 Expires: 2027-03-10 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-10-08 Status: INVALID chain Fingerprint: 5eaf15699983f98a4280ac0277ca411877477bf31f29aff018e0ebbdb83e25eb Subject Alternative Names (related infrastructure — often same operator): - gucert.xyz - infinitecrown.club - www.infinitecrown.club.gucert.xyz ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-03-10 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 07:04:52 UTC (by PhishDestroy tracker) First reported: 2026-07-27 07:26:38 UTC (abuse notice filed) Last verified: 2026-07-27 09:45:13 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa1f4-53a0-77c3-8361-01b7b8512b5d/ URLQuery: https://urlquery.net/report/819d56ac-ce54-49d8-b63e-42bc75fc7549 Wayback Machine: https://web.archive.org/web/*/infinitecrown.club.gucert.xyz crt.sh CT logs: https://crt.sh/?q=%25.infinitecrown.club.gucert.xyz Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=infinitecrown.club.gucert.xyz AlienVault OTX: https://otx.alienvault.com/indicator/domain/infinitecrown.club.gucert.xyz URLhaus: https://urlhaus.abuse.ch/host/infinitecrown.club.gucert.xyz/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 07:05:58 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] infinitecrown.club.gucert.xyz Safety Check — Phishing Detected Analysis indicates that the domain infinitecrown.club.gucert.xyz was registered on March 10, 2026 through OwnRegistrar, Inc. The authoritative name servers are dns1.webproserver.com and dns2.webproserver.com, and the domain resolves to the IPv4 address 162.245.237.212. VirusTotal has recorded nine positive detections out of ninety‑one submitted scanners, confirming that multiple security engines classify the host as malicious. The domain is currently listed on one public blocklist and is actively blocked by the PhishDestroy feed, reinforcing its reputation as a phishing infrastructure. The risk rating assigned is high and the operational status remains active as of the report date, July 27, 2026. No additional metadata such as SSL certificates, HTTP response codes, page titles, or brand targeting have been disclosed, leaving the exact content of the hosted pages unverified. Defenders should continue to deny network communications to the IP 162.245.237.212, enforce DNS sink‑hole rules for the domain, and ensure that endpoint protection solutions incorporate the latest signatures that include the nine VirusTotal detections. Monitoring of the registrar OwnRegistrar, Inc. for future domain registrations and of the webproserver.com name server pair for related activity is advised. Given the limited public intelligence, analysts should treat any traffic to this domain as high‑confidence malicious and prioritize its inclusion in intrusion‑prevention and email‑filtering policies. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-33FEF1 Favicon MD5: 0662fc451c8aa47e4b0ee6ef872e85dd TLS cert SHA-256: 5eaf15699983f98a4280ac0277ca411877477bf31f29aff018e0ebbdb83e25eb ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/infinitecrown.club.gucert.xyz/ JSON API: https://api.destroy.tools/v1/check?domain=infinitecrown.club.gucert.xyz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 204,044 domains (79,466 alive under monitoring, 123,547 confirmed takedowns/dead). Site: https://phishdestroy.io