# PhishDestroy threat dossier — member269.agency-collab-invite.com ================================================================ Fetched: 2026-06-23 22:11:21 UTC Canonical: https://phishdestroy.io/domain/member269.agency-collab-invite.com/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 24/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, Certego, Cluster25, CRDF, CyRadar, ESET, Emsisoft, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Kaspersky, Lionic, MalwareURL, Netcraft, OpenPhish, Seclookup, SOCRadar URLQuery: 3 detections Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.67.133.244 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: Gransy, s.r.o. Nameservers: adrian.ns.cloudflare.com, alex.ns.cloudflare.com Registered: 2026-04-22 Page title: Help us confirm it's you ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E8 Expires: 2026-07-21 Status: INVALID chain Fingerprint: 56193af7d81e252fcdc90421acfda53744f875a00d778777e45258bfc727c4e4 Subject Alternative Names (related infrastructure — often same operator): - agency-collab-invite.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-22 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-30 13:43:06 UTC (by PhishDestroy tracker) First reported: 2026-04-30 10:43:04 UTC (abuse notice filed) Last verified: 2026-06-23 20:20:36 UTC Neutralised: 2026-05-10 04:00:06 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019dddfa-72b3-7500-97db-0aa79b27f7f9/ URLQuery: https://urlquery.net/report/237c5926-2401-4026-adde-3025fb85c1ee Wayback Machine: https://web.archive.org/web/*/member269.agency-collab-invite.com crt.sh CT logs: https://crt.sh/?q=%25.member269.agency-collab-invite.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=member269.agency-collab-invite.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/member269.agency-collab-invite.com URLhaus: https://urlhaus.abuse.ch/host/member269.agency-collab-invite.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-30 13:44:27 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies the domain member269.agency-collab-invite.com as an active fake account verification scam designed to steal credentials under the guise of 'Help us confirm it's you'. This impostor page mimics legitimate security protocols to deceive users into surrendering login credentials. The threat level is elevated due to the sophisticated phishing tactics employed, including HTTPS encryption and urgent-sounding verbiage to bypass suspicion. This domain was flagged by 23 of 95 VirusTotal security vendors as malicious, including blocklists from OpenPhish and PhishingArmy. It resolves to IP address 172.67.133.244, is registered through Gransy, s.r.o., and was created on April 22, 2026. The certificate authority is Let's Encrypt. It appears on two active security blocklists, increasing its threat profile. Its recent creation and rapid detection by multiple vendors indicate this is a fast-moving, high-volume campaign targeting users with urgent verification requests. Given its confirmed malicious status, this domain poses an elevated risk to users who may interact with it. PhishDestroy advises immediate avoidance and blocking at the network and endpoint levels. Users should verify unexpected verification requests by visiting official sites directly, never through embedded links. Organizations are recommended to update firewall and DNS blocklists with this domain and related indicators. Report any accidental engagements to your security team or use PhishDestroy’s tools for real-time threat intelligence updates. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260430-89C331 Favicon MD5: fcb811cb5bccc7747ec3362de38756d5 TLS cert SHA-256: 56193af7d81e252fcdc90421acfda53744f875a00d778777e45258bfc727c4e4 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/member269.agency-collab-invite.com/ JSON API: https://api.destroy.tools/v1/check?domain=member269.agency-collab-invite.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 168,565 domains (12,403 alive under monitoring, 155,843 confirmed takedowns/dead). Site: https://phishdestroy.io