# PhishDestroy threat dossier — jewelsluxeshop.com ================================================================ Fetched: 2026-07-24 20:28:02 UTC Canonical: https://phishdestroy.io/domain/jewelsluxeshop.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 97/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain Flagging vendors: SOCRadar AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 196.196.232.66 (US, Los Angeles) ASN: AS46805 Angelnet Limited Hosting org: Fiber Grid Registrar: Fewmoretaps OU d/b/a Trustname.com !!! REGISTRAR INTEGRITY ALERT — Trustname / Fewmoretaps OU !!! Trustname (IANA #4318) is a shell company declaring EUR 120 annual revenue, 1 employee, negative equity, Belarusian ownership. Explicitly advertises itself as 'bulletproof' in its DNS TXT records. Primary source: https://phishdestroy.io/trustname-bulletproof-exposed Nameservers: ["ares.trustname.com", "zeus.trustname.com"] Page title: 1 HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-10-05 Status: INVALID chain Fingerprint: 1de8434b6c780973af87c6d74c090ca5d40bc7a6df7310ffc6b6cae63031a66f Subject Alternative Names (related infrastructure — often same operator): - www.jewelsluxeshop.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-19 12:38:19 UTC (by PhishDestroy tracker) Last verified: 2026-07-24 20:20:23 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-20 00:28:06 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] jewelsluxeshop.com — High-Risk Phishing Domain Targeting Retail This domain, jewelsluxeshop.com, is flagged as an active high-risk phishing site as of July 19, 2026. Infrastructure analysis reveals it resolves to IP 196.196.232.66, hosted on Fiber Grid infrastructure in the US, and is currently returning HTTP 200 responses, indicating the site remains operational. The domain is registered through Fewmoretaps OU (operating as Trustname.com), with nameservers ares.trustname.com and zeus.trustname.com, a pattern consistent with bulk-registered fraudulent domains. It appears on one security blocklist (PhishDestroy) and is included in two AlienVault OTX threat intelligence pulses, suggesting prior detection in malicious campaigns. The SSL certificate is issued by Let's Encrypt (YR1), a common choice for both legitimate and fraudulent sites due to its low-cost, automated issuance. The page title, while limited in detail, may indicate an attempt to mimic a retail or luxury goods platform, though the exact brand or service being impersonated is not confirmed in available data. No specific phishing kit or targeted brand is identified at this stage. Defenders should treat this domain as hostile until further analysis confirms otherwise. Immediate action includes blocking the domain and IP at perimeter security controls, monitoring for internal connections, and reviewing logs for prior interactions. Given its presence on multiple threat intelligence feeds and active status, this domain poses a credible risk to end users and corporate networks. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 4e2ecbd4614eeff982c23ea072935b8a TLS cert SHA-256: 1de8434b6c780973af87c6d74c090ca5d40bc7a6df7310ffc6b6cae63031a66f ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/jewelsluxeshop.com/ JSON API: https://api.destroy.tools/v1/check?domain=jewelsluxeshop.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 189,350 domains (58,576 alive under monitoring, 129,192 confirmed takedowns/dead). Site: https://phishdestroy.io