# PhishDestroy threat dossier — medilens.uz ================================================================ Fetched: 2026-07-22 17:41:26 UTC Canonical: https://phishdestroy.io/domain/medilens.uz/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 73/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 37.153.159.13 (UZ, Tashkent) ASN: ASAS35326 SUVAN-NET "SUVAN NET" LLC, UZ Hosting org: AS35326 "SUVAN NET" LLC Registrar: SUVAN NET Nameservers: dns1.ahost.uz, dns1.ahost.uz., 37.153.159.20, dns2.ahost.uz, dns2.ahost.uz., 91.98.193.184, ns1.ahost.cloud, ns2.ahost.cloud Registered: 2026-05-08 Expires: 2027-05-09 Page title: Клиника коррекции зрения Medilens Optic в Ташкенте | Ночные линзы HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-09-01 Status: INVALID chain Fingerprint: 562c0f3b0e113fc71364ccbccb221b8d657ab7ac43e36e27455c7b1680bc51a5 Subject Alternative Names (related infrastructure — often same operator): - medilens-optic.uz - muqarnas-optic.uz ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-08 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-20 10:47:03 UTC (by PhishDestroy tracker) First reported: 2026-07-20 08:48:36 UTC (abuse notice filed) Last verified: 2026-07-22 16:20:22 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f7eb3-6ba5-7449-a34f-d81a2215fd03/ URLQuery: https://urlquery.net/report/c478a3e9-b7e2-478e-8b96-5a0216a8f1c9 Wayback Machine: https://web.archive.org/web/*/medilens.uz crt.sh CT logs: https://crt.sh/?q=%25.medilens.uz Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=medilens.uz AlienVault OTX: https://otx.alienvault.com/indicator/domain/medilens.uz URLhaus: https://urlhaus.abuse.ch/host/medilens.uz/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-20 10:48:11 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] medilens.uz Safety Check — Phishing Detected medilens.uz is currently flagged as a generic phishing infrastructure. The domain was registered on May 08, 2026 through the registrar SUVAN NET and is hosted on the IP address 37.153.159.13. DNS resolution uses the authoritative servers dns1.ahost.uz and dns2.ahost.uz, both of which resolve to 37.153.159.20 and 91.98.19 respectively. As of the report date, July 20, 2026, the domain appears on a single security blocklist, PhishDestroy, indicating that at least one consortium has taken remediation action. VirusTotal records show that the domain was scanned by 95 AV engines without any positive detections, but the absence of alerts does not confirm benign behavior. The campaign remains active and its risk level is listed as under investigation, reflecting limited public intelligence on the payload or targeted victims. Uncertainty persists regarding the specific phishing page content, credential harvesting mechanisms, and any associated command‑and‑control infrastructure. Defenders should consider adding the IP address 37.153.159.13 to network‑level deny lists, enforce DNS filtering for the domain, and monitor for any traffic anomalies originating from the listed nameservers. Ongoing telemetry collection and periodic re‑scanning with multi‑engine services are recommended to detect potential changes in malicious behavior. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260720-3E3E37 Favicon MD5: d6b745acce676a75f5281f93db53a52a TLS cert SHA-256: 562c0f3b0e113fc71364ccbccb221b8d657ab7ac43e36e27455c7b1680bc51a5 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/medilens.uz/ JSON API: https://api.destroy.tools/v1/check?domain=medilens.uz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 188,258 domains (57,703 alive under monitoring, 128,922 confirmed takedowns/dead). Site: https://phishdestroy.io