# PhishDestroy threat dossier — rhoneswiss.online ================================================================ Fetched: 2026-06-09 21:13:37 UTC Canonical: https://phishdestroy.io/domain/rhoneswiss.online/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 98/100 (PhishDestroy scoring — see methodology below) Scam classification: unknown ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/92 security vendors flagged this domain Flagging vendors: Gridinsoft, Netcraft Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 198.251.84.200 (LU, Luxembourg) ASN: AS53667 FranTech Solutions Hosting org: FranTech Solutions Registrar: GMO Internet Group, Inc. d/b/a Onamae.com Nameservers: ["ns5.asurahosting.com", "ns6.asurahosting.com"] Registered: 2026-05-13 Page title: Home - Rhone Swiss Online HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-07-29 Status: INVALID chain Fingerprint: 326641d362d477bcbbf258a220a2ea9603b2756206d7962adda4d6593129df21 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-13 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-13 20:26:27 UTC (by PhishDestroy tracker) Last verified: 2026-06-09 18:32:31 UTC Neutralised: 2026-06-06 17:31:08 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e225e-3923-765d-918a-37b0ad0b0213/ Wayback Machine: https://web.archive.org/web/*/rhoneswiss.online crt.sh CT logs: https://crt.sh/?q=%25.rhoneswiss.online Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=rhoneswiss.online AlienVault OTX: https://otx.alienvault.com/indicator/domain/rhoneswiss.online URLhaus: https://urlhaus.abuse.ch/host/rhoneswiss.online/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-13 20:27:20 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies an active credential harvesting scam operating under the domain rhoneswiss.online, currently impersonating Swiss banking services to deceive unsuspecting users. This elevated-risk threat remains active as of the latest assessment, with threat actors leveraging the domain to harvest sensitive login credentials under false pretenses. Users are strongly advised to exercise extreme caution when encountering this domain or any associated communications. This domain was flagged by 1 of 95 VirusTotal security vendors, indicating minimal but notable detection across industry-standard threat intelligence platforms. The domain rhoneswiss.online was registered through GMO Internet, Inc., resolves to the IP address 198.251.84.200, and was created on June 29, 2025. Despite its recent registration, the domain exhibits several red flags, including low trust scores and limited historical legitimacy. The minimal VirusTotal detection rate suggests that broader threat intelligence networks may not yet have fully cataloged this threat, increasing the risk of exposure for unaware users. Given the elevated risk level and the domain’s active status, PhishDestroy recommends immediate action to mitigate potential exposure. Users should avoid interacting with rhoneswiss.online or any communications referencing Swiss banking services originating from this domain. Organizations are advised to update blocklists with the domain, IP address (198.251.84.200), and registrar details to prevent access. Additionally, users should report any encounters with this domain to their IT security teams or relevant cybercrime reporting platforms. Proactive monitoring of network traffic for connections to this IP is strongly encouraged to prevent credential theft or further exploitation. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: ce5ec66aecdc80cbcfbe1b93992470fe TLS cert SHA-256: 326641d362d477bcbbf258a220a2ea9603b2756206d7962adda4d6593129df21 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/rhoneswiss.online/ JSON API: https://api.destroy.tools/v1/check?domain=rhoneswiss.online Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 160,762 domains (39,376 alive under monitoring, 119,091 confirmed takedowns/dead). Site: https://phishdestroy.io