# PhishDestroy threat dossier — scotibank.com ================================================================ Fetched: 2026-07-29 17:49:11 UTC Canonical: https://phishdestroy.io/domain/scotibank.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 15/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET, Fortinet, G-Data, Gridinsoft, Kaspersky, Lionic, SOCRadar, Sophos, VIPRE, Webroot AlienVault OTX: 4 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 212.7.194.68 (NL, Amsterdam) ASN: AS60781 LeaseWeb Netherlands B.V. Hosting org: LeaseWeb Netherlands B.V. Registrar: Media Elite Holdings Limited, S.A. Nameservers: ["ns1.hastydns.com", "ns2.hastydns.com"] Page title: Where Winds Meet | Official Website ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-28 05:33:09 UTC (by PhishDestroy tracker) Last verified: 2026-07-29 16:20:23 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 05:34:21 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] scotibank.com — Banking Phishing Investigation The domain scotibank.com is currently classified as a high‑risk banking phishing site. Registration records show that the domain was created through Media Elite Holdings Limited, S.A., and it is served by the authoritative nameservers ns1.hastydns.com and ns2.hastydns.com. An HTTP request to the domain returns a 302 redirect, indicating that the site is actively forwarding traffic, a common technique used to conceal the final malicious landing page. The domain appears on a single security blocklist and is explicitly blocked by the PhishDestroy feed, confirming that at least one reputable anti‑phishing service has taken protective action. VirusTotal analysis reports that 15 of 91 scanned security vendors flag the domain, providing additional corroboration of malicious intent. The domain remains listed as active, and no evidence of takedown or remediation has been observed. Infrastructure analysis reveals no publicly disclosed IP address, SSL certificate details, or geographic hosting information, limiting the ability to attribute the hosting environment. The absence of page‑title or content metadata in the current intelligence set means that the exact phishing lure, credential‑capture mechanisms, or targeted banking brand cannot be confirmed beyond the generic banking phishing classification. Defenders should prioritize immediate containment by adding scotibank.com to DNS blocklists, URL filtering rules, and endpoint web‑reputation controls. Continuous monitoring of network flows for outbound connections to the domain is advised, as is periodic re‑scanning with multi‑engine services to capture any changes in detection scores. Organizations should also consider user education campaigns that reference the domain name, reinforcing the need to verify URLs before entering banking credentials. Given the active status and multi‑vendor detection, proactive blocking and ongoing observation constitute the most effective mitigation strategy. ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/scotibank.com/ JSON API: https://api.destroy.tools/v1/check?domain=scotibank.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,499 domains (83,266 alive under monitoring, 109,716 confirmed takedowns/dead). Site: https://phishdestroy.io