# PhishDestroy threat dossier — myservcieklarnaacco.mydomain.zone ================================================================ Fetched: 2026-07-22 19:10:56 UTC Canonical: https://phishdestroy.io/domain/myservcieklarnaacco.mydomain.zone/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Credential Phishing ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 6/91 security vendors flagged this domain Flagging vendors: Forcepoint ThreatSeeker, Fortinet, Gridinsoft, Seclookup, VIPRE, Webroot Public blocklists: listed on 2 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 62.76.234.160 (IT, Palermo) Hosting org: AS26383 Baxet Group Inc. Registrar: GoDaddy.com, LLC Nameservers: ["ns1.mydomain.zone", "ns2.mydomain.zone"] Page title: myservcieklarnaacco.mydomain.zone ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE1 Expires: 2026-10-12 Status: INVALID chain Fingerprint: a6afe58d34518f6561dcd11de8fbec88bd77b512f86b769876ef523992c558c4 Subject Alternative Names (related infrastructure — often same operator): - ftp.myservcieklarnaacco.mydomain.zone - mail.myservcieklarnaacco.mydomain.zone - pop.myservcieklarnaacco.mydomain.zone - smtp.myservcieklarnaacco.mydomain.zone - www.myservcieklarnaacco.mydomain.zone ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-22 16:47:58 UTC (by PhishDestroy tracker) First reported: 2026-07-22 14:54:42 UTC (abuse notice filed) Last verified: 2026-07-22 20:30:18 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f8a4a-fb79-7452-b106-116f2a23ddb8/ URLQuery: https://urlquery.net/report/74ac410e-0c32-44f2-9c4e-f073b78d2661 Wayback Machine: https://web.archive.org/web/*/myservcieklarnaacco.mydomain.zone crt.sh CT logs: https://crt.sh/?q=%25.myservcieklarnaacco.mydomain.zone Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=myservcieklarnaacco.mydomain.zone AlienVault OTX: https://otx.alienvault.com/indicator/domain/myservcieklarnaacco.mydomain.zone URLhaus: https://urlhaus.abuse.ch/host/myservcieklarnaacco.mydomain.zone/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-22 16:49:54 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] myservcieklarnaacco.mydomain.zone credential harvesting site This domain, myservcieklarnaacco.mydomain.zone, is currently listed as an active generic phishing infrastructure. The authoritative nameservers are ns1.justhost.ru and ns2.justhost.ru, indicating that the domain is hosted with the JustHost provider. DNS resolution points to the IPv4 address 62.76.234.160, which is the only observed hosting endpoint. The domain appears on two public blocklists and has been added to the PhishDestroy and OpenPhish feed collections, confirming that multiple threat‑intel platforms have identified it as malicious. VirusTotal reports that six of ninety‑five scanning engines flag the domain, providing independent confirmation of its malicious nature. No additional intelligence such as a page title, SSL certificate details, or HTTP response codes has been published, so the exact content served by the site remains unknown. The lack of further public observations means that analysts cannot yet determine the specific brand being spoofed or the exact phishing kit employed. Defenders should block any connections to 62.76.234.160 and add myservcieklarnaacco.mydomain.zone to local deny lists. Network monitoring rules that trigger on DNS queries for the domain or on HTTP requests to the IP can help detect compromised clients. Because the domain is still active, continuous re‑evaluation of blocklist status and periodic rescanning with VirusTotal or similar services are recommended to capture any changes in detection scores. Organizations that use the JustHost hosting service should verify whether any of their legitimate domains share the same nameservers, and consider tightening DNS filtering policies for .zone TLDs that are not explicitly required. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260722-2BC1BB Favicon MD5: 3284f09658fedd2ab1d354ac0342e37a TLS cert SHA-256: a6afe58d34518f6561dcd11de8fbec88bd77b512f86b769876ef523992c558c4 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/myservcieklarnaacco.mydomain.zone/ JSON API: https://api.destroy.tools/v1/check?domain=myservcieklarnaacco.mydomain.zone Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 188,333 domains (57,778 alive under monitoring, 128,922 confirmed takedowns/dead). Site: https://phishdestroy.io