# PhishDestroy threat dossier — phosphor.info ================================================================ Fetched: 2026-07-30 14:00:09 UTC Canonical: https://phishdestroy.io/domain/phosphor.info/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 7/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, ChainPatrol, alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet, Gridinsoft, SOCRadar AlienVault OTX: 3 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 76.223.54.146 (US, Seattle) ASN: AS16509 Amazon.com, Inc. Hosting org: AWS Global Accelerator (GLOBAL) Registrar: Dynadot Inc Nameservers: ["ns1.afternic.com", "ns2.afternic.com"] Page title: phosphor.info is for sale — Buy now for $399 | GoDaddy HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: GoDaddy.com / GoDaddy TLS Intermediate CA DV - R1v1 Expires: 2026-11-06 Status: INVALID chain Fingerprint: cfc8e1d43ad5a2ca6b5f86dbb4f073803b3b56de5c26af1c636107733ae29541 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-27 20:23:10 UTC (by PhishDestroy tracker) Last verified: 2026-07-30 12:32:29 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 20:24:20 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is phosphor.info a Phishing Site? Analysis as of July 27, 2026 indicates that the domain phosphor.info is actively serving content and returns HTTP status code 200. The domain is registered through Dynadot Inc and uses the default Afternic parking nameservers ns1.afternic.com and ns2.afternic.com. VirusTotal has recorded detections from seven of ninety‑one scanned security vendors, confirming that multiple threat‑intelligence feeds recognize malicious behavior. The domain is presently listed on one public security blocklist and has been added to the PhishDestroy mitigation list, demonstrating that at least one anti‑phishing service has taken protective action. The detection count of seven out of ninety‑one scanners reflects a moderate consensus among automated analysis engines, suggesting that the site exhibits known malicious patterns but may not yet be universally recognized. The presence on a single blocklist indicates limited exposure in public reputation feeds, yet the inclusion in PhishDestroy’s proprietary list demonstrates that specialized anti‑phishing services have identified the domain as a threat vector. The use of Afternic nameservers is a common indicator of domains that have been recently registered for malicious purposes, as these servers often host placeholder pages before the attacker points the domain to a malicious hosting provider. Because the registrar Dynadot Inc is a mainstream registrar, the domain could be leveraging legitimate registration channels to obscure its provenance. No additional infrastructure details such as IP address, autonomous system number, hosting provider, SSL certificate information, or page title have been disclosed in the available intelligence, leaving the underlying hosting environment and potential payload delivery mechanisms unverified. The limited visibility into the site’s content means that the specific phishing lure, targeted brand, or credential‑harvesting technique cannot be confirmed at this time. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: cfc8e1d43ad5a2ca6b5f86dbb4f073803b3b56de5c26af1c636107733ae29541 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/phosphor.info/ JSON API: https://api.destroy.tools/v1/check?domain=phosphor.info Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,862 domains (83,560 alive under monitoring, 110,042 confirmed takedowns/dead). Site: https://phishdestroy.io