# PhishDestroy threat dossier — quantavests.com ================================================================ Fetched: 2026-07-29 09:01:27 UTC Canonical: https://phishdestroy.io/domain/quantavests.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 5/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Fortinet, SOCRadar, Sophos, VIPRE AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- Registrar: Global Domain Group LLC Nameservers: ["5772.ns1.abovedomains.com", "5772.ns2.abovedomains.com"] ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-27 22:03:10 UTC (by PhishDestroy tracker) Last verified: 2026-07-29 09:34:07 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 22:04:07 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] quantavests.com high‑risk generic phishing campaign detected Analysis as of July 27 2026 indicates that quantavests.com is an active generic phishing infrastructure hosted under the registrar Global Domain Group LLC. The domain resolves to an HTTP endpoint that returns status code 200, suggesting a live web server. Authoritative name servers are listed as 5772.ns1.abovedomains.com and 5772.ns2.abovedomains.com, confirming the use of the Abovedomains hosting platform. Threat intelligence feeds have placed the domain on a single security blocklist, and the anti‑phishing service PhishDestroy has recorded it as blocked. VirusTotal scans show that five of ninety‑one AV engines flagged the site, providing additional corroboration of malicious intent. The risk rating assigned by internal scoring is high, and the seed identifier e8e31e tags the case for tracking. Evidence confirms the domain’s registration details but provides no public page title, brand targeting, or specific phishing kit identifiers, leaving those aspects unverified. Consequently, defenders cannot attribute the campaign to a particular victim sector or confirm which credential‑capture pages are served. The lack of additional context warrants heightened monitoring of any outbound traffic to quantavests.com and rapid containment of client requests that resolve to the domain. Recommended mitigations include adding the domain to local DNS block lists, configuring proxy or firewall rules to deny HTTP/HTTPS connections, and updating endpoint security signatures to incorporate the five VirusTotal detections. Continuous re‑assessment is advised, as future scans may reveal new indicators such as IP address attribution, SSL certificate details, or expanded blocklist coverage. ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/quantavests.com/ JSON API: https://api.destroy.tools/v1/check?domain=quantavests.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 194,182 domains (83,156 alive under monitoring, 108,406 confirmed takedowns/dead). Site: https://phishdestroy.io