# PhishDestroy threat dossier — quantumfinancialsystems.online ================================================================ Fetched: 2026-07-27 14:15:28 UTC Canonical: https://phishdestroy.io/domain/quantumfinancialsystems.online/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain Flagging vendors: Fortinet AlienVault OTX: 3 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 163.61.188.2 (US, Staten Island) ASN: AS153568 NEW DHAKA HARDWARE Hosting org: MIT Registrar: Global Domain Group LLC Nameservers: dns1.lytehosting.com, dns2.lytehosting.com, dns3.lytehosting.com, dns4.lytehosting.com Registered: 2025-12-24 Expires: 2026-12-24 Page title: Quantumfinancialsystems - Enterprise Web3 Solutions HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-09-23 Status: INVALID chain Fingerprint: 9c31c4fe5d2533f46a8fe11dafb58bea0af4bf1ff98a971e81ceed23ef4d5c03 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-12-24 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 09:08:35 UTC (by PhishDestroy tracker) First reported: 2026-07-27 12:31:47 UTC (abuse notice filed) Last verified: 2026-07-27 14:45:13 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa30e-0919-759c-a5c8-9e26d9aa70b0/ URLQuery: https://urlquery.net/report/1c8849c9-9725-4995-a3e1-d84a1538ced9 Wayback Machine: https://web.archive.org/web/*/quantumfinancialsystems.online crt.sh CT logs: https://crt.sh/?q=%25.quantumfinancialsystems.online Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=quantumfinancialsystems.online AlienVault OTX: https://otx.alienvault.com/indicator/domain/quantumfinancialsystems.online URLhaus: https://urlhaus.abuse.ch/host/quantumfinancialsystems.online/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 09:11:41 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] quantumfinancialsystems.online: Confirmed Phishing Site The domain quantumfinancialsystems.online was registered on 24 December 2025 through Global Domain Group LLC and currently resolves to the IPv4 address 163.61.188.2. The authoritative name servers dns1.lytehosting.com, dns2.lytehosting.com, dns3.lytehosting.com and dns4.lytehosting are hosted by LyteHosting, indicating that the infrastructure is provisioned on a shared hosting environment. The domain appears on a single security blocklist and is actively blocked by the PhishDestroy service, confirming that it is being used for malicious purposes. VirusTotal analysis shows that one of ninety‑one scanning engines flagged the domain, providing additional independent confirmation of its malicious nature. No further public intelligence such as page title, brand targeting, or SSL certificate details has been published, so the exact phishing lures employed remain unknown. Given the registration age of less than nine months and the presence on a blocklist, the domain is likely being used to host a credential‑harvesting site that targets financial services, consistent with the generic phishing classification. The IP address 163.61.188.2 is currently live and reachable, which means that any network that permits outbound connections to this host may be exposed to the threat. Defenders should add the domain and its associated IP to outbound filtering rules, update DNS‑based blocklists, and consider sinkholing the address if possible. Continuous monitoring of the hosting provider’s IP range for new domains that share the same name‑server set is recommended, as adversaries frequently recycle shared hosting resources for new campaigns. Because the site has not been publicly analyzed, additional investigation—such as retrieving the HTTP response, examining page content, and checking for credential‑stealing forms—should be prioritized to refine detection signatures. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-0798FB TLS cert SHA-256: 9c31c4fe5d2533f46a8fe11dafb58bea0af4bf1ff98a971e81ceed23ef4d5c03 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/quantumfinancialsystems.online/ JSON API: https://api.destroy.tools/v1/check?domain=quantumfinancialsystems.online Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 205,551 domains (80,723 alive under monitoring, 123,797 confirmed takedowns/dead). Site: https://phishdestroy.io