# PhishDestroy threat dossier — securealliance.online ================================================================ Fetched: 2026-07-29 13:58:56 UTC Canonical: https://phishdestroy.io/domain/securealliance.online/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 4/91 security vendors flagged this domain Flagging vendors: CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 192.64.119.81 (US, Atlanta) ASN: AS22612 Namecheap, Inc. Hosting org: Web-hosting.com Registrar: NameCheap, Inc. Nameservers: dns1.registrar-servers.com, dns2.registrar-servers.com Registered: 2026-07-23 Expires: 2027-07-23 Page title: securealliance.online ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-23 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-25 07:46:18 UTC (by PhishDestroy tracker) Last verified: 2026-07-29 12:49:17 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f97d2-296c-748e-8648-b8f6acb586b6/ Wayback Machine: https://web.archive.org/web/*/securealliance.online crt.sh CT logs: https://crt.sh/?q=%25.securealliance.online Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=securealliance.online AlienVault OTX: https://otx.alienvault.com/indicator/domain/securealliance.online URLhaus: https://urlhaus.abuse.ch/host/securealliance.online/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-25 07:48:59 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is securealliance.online used for credential phishing? The domain securealliance.online was registered through Namecheap Inc on July 23, 2026 and remains active as of the report date, July 25, 2026. Authoritative name servers are dns1.registrar-servers.com and dns2.registrar-servers.com, indicating the registrar’s default infrastructure. DNS resolution points to the single IPv4 address 192.64.119.81. No additional hosting details such as ASN or geographic location are disclosed in the available data. Security telemetry shows the domain is associated with credential‑phishing activity. It appears on one public blocklist and has been explicitly blocked by the PhishDestroy service, which corroborates the phishing classification. VirusTotal has recorded scans from 91 antivirus and URL‑reputation vendors; none have generated a detection at the time of analysis. Although the lack of detections does not imply benign intent, it does reflect that the sample has not triggered existing signatures. Public threat‑intel sources such as OTX, Google Safe Browsing, or similar reputation feeds do not currently list the domain, and no SSL certificate metadata, HTTP response codes, page title, or content snapshots have been published. Consequently, the visual or functional characteristics of the site remain unknown, limiting attribution of the specific phishing lure. Given the recent creation date, active status, and confirmation by a dedicated anti‑phishing blocklist, defenders should treat securealliance.online as a high‑confidence phishing indicator. Network‑level controls should deny outbound connections to the resolved IP address 192.64.119.81, and email gateways should quarantine any messages containing URLs that resolve to this domain. Continuous monitoring of VirusTotal, blocklist updates, and any future host‑header or TLS observations is recommended to adjust the risk posture as additional evidence emerges. [Updates since narrative was generated:] - WHOIS creation date: 2026-07-23 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/securealliance.online/ JSON API: https://api.destroy.tools/v1/check?domain=securealliance.online Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,478 domains (83,245 alive under monitoring, 109,716 confirmed takedowns/dead). Site: https://phishdestroy.io