# PhishDestroy threat dossier — promotionaloffer.net ================================================================ Fetched: 2026-07-28 15:48:17 UTC Canonical: https://phishdestroy.io/domain/promotionaloffer.net/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 73/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 12/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar, Forcepoint ThreatSeeker, Fortinet, G-Data, Lionic, SOCRadar, Sophos AlienVault OTX: 3 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 185.163.85.65 (SE, Stockholm) ASN: AS42695 Cleura AB Hosting org: HOLM Security Sweden AB Registrar: GoDaddy.com, LLC Nameservers: ["ns01.domaincontrol.com", "ns02.domaincontrol.com"] HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-09-13 Status: INVALID chain Fingerprint: 26b3d56132d2262fc4dc1f77f15a81aa4a332e1ec3d2cf12ff86e328b7a839c0 Subject Alternative Names (related infrastructure — often same operator): - authme-online.com - authu.net - business-receipt.info - corporate-receipt.com - cortexinsighthub.com - coupon-offer.net - credit-card-safetyorg.com - credit-card-safetyorg2.com - delivery-status.org - deliverypack.net - deliverypackage.net - digital-service.info - digitalsolution.info - direct-auth.org - fra.holmsecurity.com ... +75 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-27 22:33:10 UTC (by PhishDestroy tracker) Last verified: 2026-07-28 16:20:20 UTC Neutralised: 2026-07-28 00:57:37 UTC Current status: taken down (registrar suspended or DNS dead) ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 22:34:18 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] promotionaloffer.net leveraged in high‑risk generic phishing Analysis as of July 27, 2026 confirms that the domain promotionaloffer.net is actively used in a high‑risk generic phishing campaign. The site returns an HTTP 301 redirect, indicating it forwards visitors to another location, a technique commonly employed to obscure the final malicious destination. Registration data shows the domain was obtained through GoDaddy.com, LLC, and the authoritative nameservers are ns01.domaincontrol.com and ns02.domaincontrol.com, both typical of GoDaddy‑hosted domains. VirusTotal scans have recorded 12 detections out of 91 security vendors, demonstrating that a measurable subset of industry‑wide scanners recognize the domain as malicious. Independent threat‑filtering service PhishDestroy has also listed the domain as blocked, and it appears on a single public security blocklist, further corroborating its malicious status. No additional evidence such as Safe Browsing entries, Open Threat Exchange reports, IP or hosting details, SSL certificate information, trust scores, page title metadata, or external evidence links were observed in the available intelligence. The limited visibility of hosting infrastructure and lack of public reputation data leave the underlying command‑and‑control infrastructure partially obscured. Defenders should immediately add promotionaloffer.net to deny‑list rules in firewalls, web proxies, and email gateways. Network monitoring should flag any outbound connections to the domain’s IP address range, and DNS filtering should be configured to block resolution of the domain. Given the redirection behavior, security teams should also investigate the final landing URL for additional payload delivery or credential harvesting mechanisms. Continuous re‑evaluation is advised, as further detection data may emerge from additional scanning services or community‑shared indicators. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: 26b3d56132d2262fc4dc1f77f15a81aa4a332e1ec3d2cf12ff86e328b7a839c0 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/promotionaloffer.net/ JSON API: https://api.destroy.tools/v1/check?domain=promotionaloffer.net Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 211,607 domains (86,047 alive under monitoring, 124,530 confirmed takedowns/dead). Site: https://phishdestroy.io