# PhishDestroy threat dossier — rehearsals.bandop.com ================================================================ Fetched: 2026-07-29 17:38:46 UTC Canonical: https://phishdestroy.io/domain/rehearsals.bandop.com/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 73/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 199.36.158.100 (US, Mountain View) ASN: AS54113 Fastly, Inc. Hosting org: Google LLC Registrar: Hosting Concepts B.V. d/b/a Registrar.eu Nameservers: ["alexandra.ns.cloudflare.com", "carlos.ns.cloudflare.com"] Page title: Bandop Rehearsal HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WR3 Expires: 2026-10-17 Status: INVALID chain Fingerprint: 38c6acf22bc38b4ab5950cdfb2a0c213c42e4f92d590c9983f9232dcb78a7895 Subject Alternative Names (related infrastructure — often same operator): - ahlbadminton.com - ai-english.manlai.app - anime.world - app.deescus.com - app.lambsteps.com - app.solvius.co - applink.bevisbytheo.com - applink.eon.hu - aptivos.com - arcade81.com - auth.game-insight.com - auth.kavit.in - auth.us.formapprovals.com - awoodsmedia.com - bestfileconvert.com ... +84 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-28 01:03:08 UTC (by PhishDestroy tracker) Last verified: 2026-07-29 16:20:24 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 01:04:23 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] rehearsals.bandop.com used for credential phishing Domain rehearsals.bandop.com is currently active and returns HTTP status code 200 when accessed. The domain appears on a single security blocklist and is actively blocked by the PhishDestroy filtering service, indicating that at least one commercial anti‑phishing solution has identified it as malicious. Registration records show the domain was created through Hosting Concepts B.V., operating under the Registrar.eu brand, providing a legitimate‑looking registrar trace. DNS resolution is delegated to Cloudflare, using the nameservers alexandra.ns.cloudflare.com and carlos.ns.cloudflare.com, which suggests the infrastructure benefits from Cloudflare’s CDN and DDoS mitigation services. VirusTotal analysis confirms the domain has been scanned by 91 antivirus and URL‑reputation engines; none of the engines reported a detection as of the report date, though the lack of a detection does not constitute a safety guarantee. No additional data such as SSL certificate details, page title, or observed payloads are presently available, leaving the full scope of the phishing campaign uncertain. Defenders should continue to monitor the domain for changes in hosting, content, or detection status, enforce blocking at network perimeter and endpoint security layers, and add the indicator to internal blocklists. Sharing the domain with threat‑intelligence sharing platforms and conducting passive DNS or sandbox analysis of any retrieved content will help uncover further malicious activity and reduce exposure to credential‑phishing attempts. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 870f72e81a7119cdb62a958e2f641963 TLS cert SHA-256: 38c6acf22bc38b4ab5950cdfb2a0c213c42e4f92d590c9983f9232dcb78a7895 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/rehearsals.bandop.com/ JSON API: https://api.destroy.tools/v1/check?domain=rehearsals.bandop.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,499 domains (83,266 alive under monitoring, 109,716 confirmed takedowns/dead). Site: https://phishdestroy.io