# PhishDestroy threat dossier — sedriton.net.safeharbourlimited.com ================================================================ Fetched: 2026-07-28 08:03:27 UTC Canonical: https://phishdestroy.io/domain/sedriton.net.safeharbourlimited.com/ ## VERDICT ---------------------------------------------------------------- ACTIVE THREAT — multiple warning signs Composite threat score: 56/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 10/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, BitDefender, CyRadar, ESET, Fortinet, G-Data, Netcraft, SOCRadar, Sophos, VIPRE Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 213.111.154.80 (NL, Haarlem) ASN: AS43641 SOLLUTIUM EU Sp z.o.o. Hosting org: AMS Colo Registrar: Ultahost, Inc. Nameservers: ["ns3-ams.v-sys.org", "ns4-ams.v-sys.org"] HTTP response: 302 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-09-08 Status: INVALID chain Fingerprint: cde29e85cf420bdcb0f8ad6bec29cc64851f3c04afd611647cda6cec9252cf08 Subject Alternative Names (related infrastructure — often same operator): - goldenguardlimited.com - safeharbourlimited.com - sedriton.net - trustebridgelimited.com - www.goldenguardlimited.com.safeharbourlimited.com - www.sedriton.net.safeharbourlimited.com - www.trustebridgelimited.com.safeharbourlimited.com - www.vistatrad.com.safeharbourlimited.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-28 05:33:09 UTC (by PhishDestroy tracker) Last verified: 2026-07-28 08:30:49 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 05:34:16 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] sedriton.net.safeharbourlimited.com – Phishing Site Detected Analysis of the domain sedriton.net.safeharbourlimited.com shows that it remains operational as of the report date, July 28, 2026. DNS queries resolve to the authoritative name servers ns3-ams.v-sys.org and ns4-ams.v-sys.org, which are hosted by the V‑Sys infrastructure in the Amsterdam region. The WHOIS record lists Ultahost, Inc. as the registrar, confirming that the domain was acquired through a commercial hosting provider. An HTTP request to the root URL returns a 302 status code, indicating an immediate redirect that is typical of phishing infrastructure designed to forward victims to a malicious landing page. The domain appears on a single public security blocklist and is actively blocked by the PhishDestroy filtering service, demonstrating that at least one defensive platform has identified it as abusive. VirusTotal analysis shows that 10 out of 91 scanned security engines flagged the domain as malicious, providing independent confirmation of its threat profile. No additional context such as page title, SSL certificate details, or hosting IP address is publicly disclosed, leaving the precise payload and target brand undefined. Given the observed redirect behavior, registrar information, and multiple vendor detections, defenders should treat the domain as high‑risk. Recommended mitigations include adding the domain to network and endpoint blocklists, configuring web proxies to deny HTTP 302 responses from this host, and monitoring DNS queries for the associated name servers. Continuous re‑scanning with VirusTotal or similar services is advised to capture any changes in the detection count. Organizations should also consider reporting the domain to additional threat‑intel sharing platforms to broaden coverage across security products. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: c5d2c4a9059872f0f87b1d42c8360e13 TLS cert SHA-256: cde29e85cf420bdcb0f8ad6bec29cc64851f3c04afd611647cda6cec9252cf08 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/sedriton.net.safeharbourlimited.com/ JSON API: https://api.destroy.tools/v1/check?domain=sedriton.net.safeharbourlimited.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 210,284 domains (97,379 alive under monitoring, 111,874 confirmed takedowns/dead). Site: https://phishdestroy.io