# PhishDestroy threat dossier — sge.france-monuments.com ================================================================ Fetched: 2026-07-28 22:22:20 UTC Canonical: https://phishdestroy.io/domain/sge.france-monuments.com/ ## VERDICT ---------------------------------------------------------------- ACTIVE THREAT — multiple warning signs Composite threat score: 57/100 (PhishDestroy scoring — see methodology below) Scam classification: Credential Phishing ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/91 security vendors flagged this domain Flagging vendors: SOCRadar, Webroot Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 165.245.219.4 (DE, Frankfurt am Main) ASN: AS14061 DigitalOcean, LLC Hosting org: DigitalOcean, LLC Registrar: HOSTINGER operations, UAB Nameservers: ["clayton.ns.cloudflare.com", "grace.ns.cloudflare.com"] Page title: Sign in — Jet Set Dash HTTP response: 302 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE2 Expires: 2026-09-23 Status: INVALID chain Fingerprint: ee4f5e186605245846804d2a8e32ec79dfc707fb0dc1a87da684b2fd1f2acd15 Subject Alternative Names (related infrastructure — often same operator): - chateauversaillesticket.com - egypt-monuments.com - france-monuments.com - lelouvrebillet.com - sge.chateauversaillesticket.com - sge.egypt-monuments.com - sge.lelouvrebillet.com - sge.thailand-monuments.com - sge.thelondoneyetickets.com - sge.tickets-grandegyptianmuseum.com - sge.ticketsgem.com - sge.tivoligardenstickets.com - sge.uffizigalleries.com - thailand-monuments.com - thelondoneyetickets.com ... +15 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-28 05:23:09 UTC (by PhishDestroy tracker) Last verified: 2026-07-29 00:20:26 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 05:24:38 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is sge.france-monuments.com a phishing site for credentials? Analysis of the domain sge.france-monuments.com on July 28, 2026, indicates it is actively involved in phishing operations targeting user credentials. The domain is registered through HOSTINGER operations, UAB, and uses Cloudflare nameservers clayton.ns.cloudflare.com and grace.ns.cloudflare.com, a configuration commonly observed in phishing infrastructure to obscure hosting details and evade takedowns. At the time of assessment, the domain returns an HTTP 302 redirect status, suggesting it may be redirecting visitors to another malicious or deceptive page, though the final destination remains unconfirmed in available data. VirusTotal detection results show 2 of 91 security vendors flagging the domain as malicious, a modest but notable signal given the low detection threshold often seen in early-stage phishing campaigns. The domain appears on one security blocklist, specifically PhishDestroy, which specializes in credential-theft detection. No additional context regarding the targeted brand, phishing kit, or specific lure type is present in current intelligence. The exact content of the site has not been analyzed, so the precise nature of the credential harvesting—whether targeting corporate, financial, or personal accounts—remains uncertain. Defenders are advised to treat this domain as high-risk. Network-level blocking at the DNS or proxy layer is recommended, particularly for organizations with exposure to credential-based attacks. Security teams should monitor for connections to sge.france-monuments.com in web logs, endpoint telemetry, and email filtering systems, as phishing domains of this nature are frequently distributed via email or malvertising. Given the use of Cloudflare, IP-based blocking may be ineffective, reinforcing the need for domain-specific controls. Further investigation into associated redirects, SSL certificates, and hosting patterns may reveal additional infrastructure linked to this campaign. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: ee4f5e186605245846804d2a8e32ec79dfc707fb0dc1a87da684b2fd1f2acd15 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/sge.france-monuments.com/ JSON API: https://api.destroy.tools/v1/check?domain=sge.france-monuments.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 208,135 domains (82,977 alive under monitoring, 124,126 confirmed takedowns/dead). Site: https://phishdestroy.io