# PhishDestroy threat dossier — iptvsport.net ================================================================ Fetched: 2026-07-22 07:49:55 UTC Canonical: https://phishdestroy.io/domain/iptvsport.net/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 83/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, Fortinet URLQuery: 2 detections Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 185.192.125.137 (NL, Rotterdam) ASN: ASAS200514 KnownSRV KnownSRV Ltd., GB Hosting org: AS200514 KnownSRV Ltd. Registrar: ENOM, INC. Nameservers: ns1.iptvsport.net, ns2.iptvsport.net Registered: 2026-03-06 Expires: 2028-03-06 Page title: IPTV Kopen in Nederland | Beste IPTV Abonnementen 2026 HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-10-08 Status: INVALID chain Fingerprint: d68eeed2c7ae2399f975460eb550155b34c041c44d7e0a48418474a2372073b2 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-03-06 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-12 17:36:00 UTC (by PhishDestroy tracker) First reported: 2026-07-12 19:23:46 UTC (abuse notice filed) Last verified: 2026-07-22 08:20:25 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f56f8-2b98-745a-839f-39c9dd7e819e/ URLQuery: https://urlquery.net/report/2fb38bd0-f46f-4b9e-a274-a9ebfe930007 Wayback Machine: https://web.archive.org/web/*/iptvsport.net crt.sh CT logs: https://crt.sh/?q=%25.iptvsport.net Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=iptvsport.net AlienVault OTX: https://otx.alienvault.com/indicator/domain/iptvsport.net URLhaus: https://urlhaus.abuse.ch/host/iptvsport.net/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-12 17:50:11 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] iptvsport.net — Generic Phishing Investigation iptvsport.net was registered on 2026-03-06 through ENOM, INC. The domain is currently active and resolves to the IPv4 address 185.192.125.137. Both authoritative name servers, ns1.iptvsport.net and ns2.iptvsport.net, are hosted under the same domain, suggesting the operator controls the full DNS zone. No detections have been reported on VirusTotal (0/95 scans), indicating that the site has not yet been flagged by public scanners, but the absence of detections does not imply benign intent. The domain has been classified as a generic_phishing infrastructure. Although the public web content was not provided, the combination of a recently created domain, dedicated name servers, and the active status aligns with typical phishing deployment patterns where attackers use short‑lived domains to host credential‑harvesting pages. The IP address 185.192.125.137 is publicly routable and does not belong to a known cloud‑provider block, which may indicate the use of a residential or VPS hosting service to reduce attribution risk. Current intelligence lacks details on the specific phishing campaign, target brand, or malicious payload. No malware hashes, URL snapshots, or email samples have been linked to the domain, leaving the exact phishing vector uncertain. The registrar ENOM, INC. is a popular service for both legitimate and malicious actors, and the use of self‑hosted name servers could be an attempt to avoid registrar‑level takedown. Observers should watch for any future association of the domain with phishing emails, credential‑stealing pages, or redirects to known malicious repositories. Defenders are advised to block traffic to iptvsport.net and to the IP 185.192.125.137 at network perimeter devices. Continuous monitoring of DNS queries for the domain and its name servers should be instituted, and any sighting of related phishing content should be reported to relevant abuse contacts. Because the infrastructure is still under investigation, threat hunters should include the domain in indicator‑of‑compromise (IOC) sets and correlate it with endpoint logs to detect potential exploitation. [Updates since narrative was generated:] - VirusTotal detections: now 2/91 (narrative was written when count was lower) ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260712-B0D304 Favicon MD5: e19f2d57b1d4063cdb7feb1abc017d18 TLS cert SHA-256: d68eeed2c7ae2399f975460eb550155b34c041c44d7e0a48418474a2372073b2 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/iptvsport.net/ JSON API: https://api.destroy.tools/v1/check?domain=iptvsport.net Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 187,759 domains (57,336 alive under monitoring, 128,779 confirmed takedowns/dead). Site: https://phishdestroy.io