# PhishDestroy threat dossier — omega-smart.net ================================================================ Fetched: 2026-07-28 21:30:40 UTC Canonical: https://phishdestroy.io/domain/omega-smart.net/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 10/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET, Fortinet, G-Data, Gridinsoft, Netcraft, VIPRE AlienVault OTX: 3 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 192.142.53.228 (NL, Amsterdam) ASN: AS214036 Ultahost, Inc. Hosting org: Ultahost Inc Registrar: Ultahost, Inc. Nameservers: ns1.ultahost.com, ns2.ultahost.com, ns3.ultahost.com, ns4.ultahost.com Registered: 2025-05-14 Expires: 2027-05-14 Page title: omega-smart.net HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE1 Expires: 2026-10-17 Status: INVALID chain Fingerprint: fd11f96278e78b294ed17bf1771b3903ccee4d4ae1b12b6c74186822e5e6a048 Subject Alternative Names (related infrastructure — often same operator): - www.omega-smart.net ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-05-14 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 07:29:51 UTC (by PhishDestroy tracker) First reported: 2026-07-27 08:33:43 UTC (abuse notice filed) Last verified: 2026-07-28 21:04:07 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa230-64fc-7377-b5f0-9b5133e85305/ URLQuery: https://urlquery.net/report/08c1b606-a91d-4696-bc48-773091edfbbf Wayback Machine: https://web.archive.org/web/*/omega-smart.net crt.sh CT logs: https://crt.sh/?q=%25.omega-smart.net Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=omega-smart.net AlienVault OTX: https://otx.alienvault.com/indicator/domain/omega-smart.net URLhaus: https://urlhaus.abuse.ch/host/omega-smart.net/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 07:34:35 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] omega-smart.net: Confirmed Phishing Site Analysis of omega-smart.net indicates that the domain is actively being used for phishing. The domain resolves to the IPv4 address 192.142.53.228 and is hosted on infrastructure provided by Ultahost, Inc., as evidenced by the four authoritative name servers ns1.ultahost.com through ns4.ultahost.com. Registration data shows the domain was created on 14 May 2025 and remains under the same registrar, confirming a relatively recent creation window that aligns with typical abuse timelines. Threat intelligence sources have flagged the domain. It appears on one public blocklist and is specifically listed as blocked by the PhishDestroy service, demonstrating that at least one anti‑phishing community has taken action against it. VirusTotal scans have returned detections from ten of ninety‑one security vendors, indicating that multiple independent scanners have identified malicious characteristics. Additionally, AlienVault OTX records the domain in three separate threat‑intel pulses, further corroborating its malicious reputation. The available data does not include a current HTTP response code, SSL certificate details, or page title, so the exact content served by the site cannot be confirmed at this time. Consequently, the precise phishing lure—whether it targets credential capture for a particular brand or a generic credential‑theft page—remains unknown. However, the combination of blocklist presence, vendor detections, and OTX pulses provides sufficient evidence for a high‑confidence classification as a phishing resource. Defenders should add 192.142.53.228 to network‑level deny lists and block any DNS resolution of omega‑smart.net. Security gateways that reference the PhishDestroy blocklist should already be rejecting traffic to the domain, but organizations that rely on other feeds should explicitly incorporate the domain and its name‑server set into their threat‑intelligence feeds. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-FC9605 Favicon MD5: fd6c20baa22d769f5fa44526e6267b50 TLS cert SHA-256: fd11f96278e78b294ed17bf1771b3903ccee4d4ae1b12b6c74186822e5e6a048 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/omega-smart.net/ JSON API: https://api.destroy.tools/v1/check?domain=omega-smart.net Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 208,135 domains (82,977 alive under monitoring, 124,126 confirmed takedowns/dead). Site: https://phishdestroy.io