# PhishDestroy threat dossier — paramount-2026cwc-fifa.com ================================================================ Fetched: 2026-07-31 06:22:51 UTC Canonical: https://phishdestroy.io/domain/paramount-2026cwc-fifa.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 6/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Fortinet, Gridinsoft, SOCRadar AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 168.76.64.132 (HK, Tseung Kwan O) ASN: AS137951 ASLINE LIMITED Hosting org: Free State Education Department Registrar: GMO Internet Group, Inc. d/b/a Onamae.com Nameservers: ["a3.share-dns.com", "b3.share-dns.net"] Page title: 404 Not Found HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: unknown Expires: 2036-07-13 Status: INVALID chain Fingerprint: c5af460b013608a6548313e3ab8f5368cab02f7879e5035c4827cf418b9581aa ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-27 18:13:09 UTC (by PhishDestroy tracker) Last verified: 2026-07-31 08:20:24 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 18:14:40 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] paramount-2026cwc-fifa.com Safety Check — FIFA World Cup Analysis of the domain paramount-2026cwc-fifa.com indicates active phishing infrastructure targeting the 2026 FIFA World Cup. Registered through GMO Internet Group, Inc. d/b/a Onamae.com, the domain remains operational as of July 27, 2026, returning an HTTP 200 status code. Infrastructure analysis reveals nameservers hosted on a3.share-dns.com and b3.share-dns.net, a pattern consistent with previously observed phishing campaigns leveraging shared DNS providers for rapid domain rotation. The domain appears on one security blocklist, specifically PhishDestroy, and is flagged by 6 of 91 security vendors on VirusTotal, confirming detection by multiple independent engines. No additional context regarding the specific phishing kit, targeted brand, or exact lure mechanism is currently available in the intelligence feed. The inclusion of '2026cwc' and 'fifa' in the domain suggests an intent to exploit interest in the upcoming FIFA World Cup, though the exact content hosted on the site has not been analyzed. Defenders are advised to block the domain at the DNS or proxy level, monitor for connections to the associated nameservers, and correlate any internal access attempts with user-reported phishing lures. Given the domain's active status and detection by multiple vendors, it should be treated as high-risk until further analysis or takedown occurs. No indicators of compromise (IOCs) beyond the domain and nameservers are provided in the current intelligence feed. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: c5af460b013608a6548313e3ab8f5368cab02f7879e5035c4827cf418b9581aa ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/paramount-2026cwc-fifa.com/ JSON API: https://api.destroy.tools/v1/check?domain=paramount-2026cwc-fifa.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 196,190 domains (84,176 alive under monitoring, 27,265 confirmed neutralized). Site: https://phishdestroy.io