# PhishDestroy threat dossier — mastercloudventure.com ================================================================ Fetched: 2026-06-26 19:28:07 UTC Canonical: https://phishdestroy.io/domain/mastercloudventure.com/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 90/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/95 security vendors flagged this domain Flagging vendors: CRDF, Netcraft URLQuery: 2 detections Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 198.251.89.30 (LU, Luxembourg) ASN: AS53667 FranTech Solutions Hosting org: FranTech Solutions Registrar: Sav.com, LLC Nameservers: ns23.asurahosting.com, ns23.my-control-panel.com, ns24.asurahosting.com, ns24.my-control-panel.com Registered: 2026-01-14 Page title: Mastercloudventure– Safe investment with Mastercloudventure HTTP response: 429 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-08-14 Status: INVALID chain Fingerprint: 52482734fe7ae9ae072264e2227a821fc9469e2f3a3c1a78d0989362e0fe886d Subject Alternative Names (related infrastructure — often same operator): - mastercloudventure.com.orbix-finance.com - www.mastercloudventure.com.orbix-finance.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-01-14 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-18 16:59:07 UTC (by PhishDestroy tracker) First reported: 2026-05-18 14:00:32 UTC (abuse notice filed) Last verified: 2026-06-26 20:20:34 UTC Neutralised: 2026-06-06 17:30:36 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e3b61-187a-75ae-b898-9082dc427b68/ URLQuery: https://urlquery.net/report/376aff63-f085-44c3-b23a-5c6e9bd4bab2 Wayback Machine: https://web.archive.org/web/*/mastercloudventure.com crt.sh CT logs: https://crt.sh/?q=%25.mastercloudventure.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=mastercloudventure.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/mastercloudventure.com URLhaus: https://urlhaus.abuse.ch/host/mastercloudventure.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-18 16:59:56 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies mastercloudventure.com as an active cloud storage-themed phishing domain designed to steal sensitive files and login credentials from unsuspecting users. The threat actor behind this domain mimics the appearance of legitimate cloud storage services to deceive victims into uploading personal documents or entering their account passwords. This domain resolves to IP address 198.251.89.30 and leverages a Let's Encrypt SSL certificate to appear trustworthy, a common tactic in phishing campaigns to bypass browser security warnings. Users who interact with this site risk exposing confidential data or downloading malware disguised as legitimate files. This domain was registered on January 14, 2026, through Sav.com, LLC, and is already flagged by 2 out of 95 VirusTotal security vendors as malicious. Its recent creation date and low detection rate make it particularly dangerous, as it has had minimal exposure to security tools. The combination of a recently registered domain, low detection rate, and the use of a free SSL certificate highlights the sophistication of this threat actor's tactics. Security researchers should monitor this domain closely, as it may expand its infrastructure or shift to more aggressive phishing techniques. If you visited mastercloudventure.com, avoid entering any login credentials or uploading sensitive files. Check your accounts for unauthorized activity and change passwords if you used the same credentials elsewhere. Report the domain to your IT team or security vendor, and ensure your device is scanned for malware. Block this domain at your network perimeter to prevent further access. Stay vigilant for similar cloud storage-themed phishing attempts, as these attacks often evolve to exploit current trends and user trust in cloud services. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260518-CEB9A7 Favicon MD5: a63a63baa153b630e69d807ad11e19e6 TLS cert SHA-256: 52482734fe7ae9ae072264e2227a821fc9469e2f3a3c1a78d0989362e0fe886d ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/mastercloudventure.com/ JSON API: https://api.destroy.tools/v1/check?domain=mastercloudventure.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 170,580 domains (12,269 alive under monitoring, 157,922 confirmed takedowns/dead). Site: https://phishdestroy.io