# PhishDestroy threat dossier — mtamsakllugian.gitbook.io ================================================================ Fetched: 2026-07-31 12:52:45 UTC Canonical: https://phishdestroy.io/domain/mtamsakllugian.gitbook.io/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 78/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 16/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, BitDefender, Ermes, ESET, Emsisoft, Forcepoint ThreatSeeker, Fortinet, G-Data, Kaspersky, LevelBlue, Lionic, MalwareURL, Netcraft, Sophos, VIPRE, Webroot Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 104.18.40.47 Registrar: Cloudflare, Inc Nameservers: dahlia.ns.cloudflare.com, hugh.ns.cloudflare.com Registered: 2014-03-30 Expires: 2031-03-30 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2014-03-30 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-31 13:06:46 UTC (by PhishDestroy tracker) Last verified: 2026-07-31 14:00:06 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fb7d9-b743-72be-9a9d-0f9ac740cce1/ Wayback Machine: https://web.archive.org/web/*/mtamsakllugian.gitbook.io crt.sh CT logs: https://crt.sh/?q=%25.mtamsakllugian.gitbook.io Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=mtamsakllugian.gitbook.io AlienVault OTX: https://otx.alienvault.com/indicator/domain/mtamsakllugian.gitbook.io URLhaus: https://urlhaus.abuse.ch/host/mtamsakllugian.gitbook.io/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-31 13:10:07 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] mtamsakllugian.gitbook.io — Cloudflare-hosted phishing page Analysis of mtamsakllugian.gitbook.io indicates a high-risk phishing domain hosted on Cloudflare infrastructure. The domain was registered on March 30, 2014, through Cloudflare, Inc., and currently resolves to IP address 104.18.40.47. Nameservers are dahlia.ns.cloudflare.com and hugh.ns.cloudflare.com, confirming Cloudflare as the DNS provider. As of July 31, 2026, the domain remains active and is flagged by 16 of 91 security vendors on VirusTotal, though the specific detection rules or payloads are not detailed in available intelligence. It appears on three security blocklists, including PhishDestroy, MetaMask, and SEAL, suggesting recognition as a phishing threat by multiple independent sources. No brand target or phishing kit is specified in the available data, and the exact content of the page has not been analyzed. Defenders should treat this domain as malicious, block access at the network level, and monitor for connections to 104.18.40.47 or requests to the gitbook.io subdomain. The long registration age does not reduce risk, as phishing domains frequently abuse legitimate hosting platforms with established reputations. Further investigation into associated payloads or redirect chains is recommended if user interactions are reported. ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/mtamsakllugian.gitbook.io/ JSON API: https://api.destroy.tools/v1/check?domain=mtamsakllugian.gitbook.io Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 196,353 domains (84,073 alive under monitoring, 27,268 confirmed neutralized). Site: https://phishdestroy.io