# PhishDestroy threat dossier — lh.gecnnrl.com ================================================================ Fetched: 2026-07-27 22:42:40 UTC Canonical: https://phishdestroy.io/domain/lh.gecnnrl.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Credential Phishing ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 6/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Cluster25, CRDF, Gridinsoft, SOCRadar, Webroot URLQuery: 2 detections Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 198.71.59.189 (US, New York City) ASN: ASAS8560 IONOS-AS IONOS SE, DE Hosting org: AS8560 IONOS SE Registrar: IONOS SE Nameservers: ns1.fanoermano.info, ns2.fanoermano.info Registered: 2026-06-27 Expires: 2027-06-27 Page title: Christmas Piano - Free HTML CSS Template HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-09-26 Status: INVALID chain Fingerprint: 7ae9991d8f9f8ec85eb891d72db163d851ab0ca54870e8fa1c8cd9c5b72bc7b5 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-06-27 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-25 02:22:10 UTC (by PhishDestroy tracker) First reported: 2026-07-25 00:25:40 UTC (abuse notice filed) Last verified: 2026-07-27 20:20:26 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f96a5-9be8-755b-aca8-5f4b9a708ced/ URLQuery: https://urlquery.net/report/852dd72e-17b0-44a1-becc-959a668e9e7c Wayback Machine: https://web.archive.org/web/*/lh.gecnnrl.com crt.sh CT logs: https://crt.sh/?q=%25.lh.gecnnrl.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=lh.gecnnrl.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/lh.gecnnrl.com URLhaus: https://urlhaus.abuse.ch/host/lh.gecnnrl.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-25 02:25:14 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] lh.gecnnrl.com credential harvesting campaign detected This domain, lh.gecnnrl.com, is currently classified as an active generic phishing infrastructure. The domain was registered through IONOS SE on June 27, 2026 and resolves to the IPv4 address 198.71.59.189. Authoritative name servers are ns1.fanoermano.info and ns2.fanoermano.info, which are not associated with the registrar and may indicate an attempt to obscure hosting details. VirusTotal reports that six of ninety‑one scanned security vendors flag the domain, providing early evidence of malicious behavior. The domain appears on two reputable phishing blocklists, PhishDestroy and OpenPhish, confirming that external threat‑intelligence feeds have already identified it as malicious. No public SSL certificate information, HTTP response codes, or page title data have been released, so the exact content served by the site remains unverified. Defenders should immediately block network traffic to 198.71.59.189 and add lh.gecnnrl.com to local deny lists. Monitoring of DNS queries for the domain and its authoritative name servers is recommended to detect potential lateral use. Because the domain is newly created, its short age combined with the observed detection metrics suggests a deliberate, fast‑track deployment for credential harvesting. Security teams should also watch for related subdomains that may share the same name server infrastructure, and consider enriching alerts with the known blocklist identifiers. Continuous re‑evaluation of the domain’s status on VirusTotal and additional sandbox analysis is advised should a sample be captured. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260725-F23E50 TLS cert SHA-256: 7ae9991d8f9f8ec85eb891d72db163d851ab0ca54870e8fa1c8cd9c5b72bc7b5 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/lh.gecnnrl.com/ JSON API: https://api.destroy.tools/v1/check?domain=lh.gecnnrl.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 207,542 domains (82,445 alive under monitoring, 124,066 confirmed takedowns/dead). Site: https://phishdestroy.io