# PhishDestroy threat dossier — jtkmetalcraft.com.au ================================================================ Fetched: 2026-06-26 19:19:41 UTC Canonical: https://phishdestroy.io/domain/jtkmetalcraft.com.au/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Generic Phishing Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users (type: content_divergence) (score: 1/6) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 12/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar, Forcepoint ThreatSeeker, Fortinet, G-Data, LevelBlue, Lionic, SOCRadar Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 163.47.74.193 (AU, Sydney) ASN: ASAS38719 DREAMSCAPE-AS-AP - Dreamscape Networks Limited, AU Hosting org: AS38719 Dreamscape Networks Limited Registrar: Web Address Registration Pty Ltd Nameservers: ns1.syrahost.com, ns2.syrahost.com ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-08-04 Status: INVALID chain Fingerprint: efe383f9e86ae3594637b91187b1d5934627e598d461a46d5347f56640d58551 Subject Alternative Names (related infrastructure — often same operator): - cpanel.jtkmetalcraft.com.au - cpcalendars.jtkmetalcraft.com.au - cpcontacts.jtkmetalcraft.com.au - ipv6.jtkmetalcraft.com.au - mail.jtkmetalcraft.com.au - webdisk.jtkmetalcraft.com.au - webmail.jtkmetalcraft.com.au - www.jtkmetalcraft.com.au ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-06-23 00:31:25 UTC (by PhishDestroy tracker) Last verified: 2026-06-26 20:20:34 UTC Neutralised: 2026-06-23 06:17:55 UTC Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019ef174-f957-74de-8e56-513ee671d989/ Wayback Machine: https://web.archive.org/web/*/jtkmetalcraft.com.au crt.sh CT logs: https://crt.sh/?q=%25.jtkmetalcraft.com.au Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=jtkmetalcraft.com.au AlienVault OTX: https://otx.alienvault.com/indicator/domain/jtkmetalcraft.com.au URLhaus: https://urlhaus.abuse.ch/host/jtkmetalcraft.com.au/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-23 09:54:08 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] This report analyzes the domain jtkmetalcraft.com.au based on available data. The site's page title and specific brand information are not provided, but the domain name suggests an association with a metal crafting business. The primary threat posed is malicious activity, as evidenced by security vendor detections and the presence of cloaking, specifically content_divergence, which indicates the site serves different content to users and scanners to evade analysis. Technical analysis reveals the domain is flagged by 12 out of 95 VirusTotal vendors, including ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, and CRDF. It is listed on one blocklist. The domain is registered through Web Address Registration Pty Ltd and resolves to IP address 163.47.74.193, located in Australia and hosted on AS38719 Dreamscape Networks Limited. The site uses a Let's Encrypt SSL certificate (R12) and nameservers ns1.syrahost.com and ns2.syrahost.com. The domain risk score is 88. As of the analysis, the site is reported as down or offline. The high risk score of 88, combined with multiple security vendor detections and cloaking, indicates a significant threat level. The site should be avoided and treated as malicious. [Updates since narrative was generated:] - Public blocklists: now listed on 1 feed ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: efe383f9e86ae3594637b91187b1d5934627e598d461a46d5347f56640d58551 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/jtkmetalcraft.com.au/ JSON API: https://api.destroy.tools/v1/check?domain=jtkmetalcraft.com.au Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 170,580 domains (12,269 alive under monitoring, 157,922 confirmed takedowns/dead). Site: https://phishdestroy.io