# PhishDestroy threat dossier — shop.gearsofwar.com ================================================================ Fetched: 2026-07-30 05:08:43 UTC Canonical: https://phishdestroy.io/domain/shop.gearsofwar.com/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 73/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 20.112.250.133 (US, Des Moines) ASN: AS8075 Microsoft Corporation Hosting org: Microsoft Azure Cloud (centralus) Registrar: Nom-iq Ltd. dba COM LAUDE Nameservers: ["ns1-07.azure-dns.com", "ns2-07.azure-dns.net", "ns3-07.azure-dns.org", "ns4-07.azure-dns.info"] Page title: Gears of War: Never Fight Alone – FINAL BOSS HTTP response: 301 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Microsoft Corporation / Microsoft TLS G2 RSA CA OCSP 16 Expires: 2026-12-16 Status: INVALID chain Fingerprint: cde181ac7c588c2877fa9be102a19595740e0a3e3903b3781d117a6e124b0f97 Subject Alternative Names (related infrastructure — often same operator): - 2010office.it - adatum.ai - ai.fluentui.dev - aiandyou.today - aielectionsaccord.com - aiotlabs.microsoft.com - airlift.microsoft.com - aiusecaseexplorer.microsoft.com - apc.delve.office.com - auth.flip.com - bestxboxgames.com - blog.aspire.dev - book.ms - boulder-innovations.com - can.delve.office.com ... +182 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-28 06:03:08 UTC (by PhishDestroy tracker) Last verified: 2026-07-30 04:20:21 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 06:05:37 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] shop.gearsofwar.com — Generic Phishing Investigation Report As of July 28, 2026, the domain shop.gearsofwar.com is under investigation for potential phishing activity. The domain is registered through Nom-iq Ltd. dba COM LAUDE, indicating a possible use of a privacy or proxy registration service to obscure the true owner. Analysis reveals that the domain currently returns an HTTP status code of 301, suggesting a permanent redirect to another location. This redirect behavior may be leveraged to guide victims to a different malicious site, making the infrastructure more flexible and harder to track. The domain appears on one security blocklist, specifically PhishDestroy, which flags it as suspicious. This listing indicates that the domain has been identified as potentially harmful by at least one security service, though the broader community of detection vendors has not yet flagged it. The nameservers used by the domain are ns1-07.azure-dns.com, ns2-07.azure-dns.net, ns3-07.azure-dns.org, and ns4-07.azure-dns.info, suggesting that the domain is hosted on Microsoft Azure infrastructure. This hosting choice could provide the attackers with robust and scalable resources. Given the current status of the domain as active and its presence on a security blocklist, defenders should exercise caution and consider blocking or monitoring access to this domain. Further investigation is required to determine the exact nature of the threat and the destination of the redirect. Until more concrete evidence is available, it is advisable to treat shop.gearsofwar.com as a potential phishing site and to alert users to the risks associated with visiting or interacting with it. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: cde181ac7c588c2877fa9be102a19595740e0a3e3903b3781d117a6e124b0f97 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/shop.gearsofwar.com/ JSON API: https://api.destroy.tools/v1/check?domain=shop.gearsofwar.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,572 domains (93,397 alive under monitoring, 99,913 confirmed takedowns/dead). Site: https://phishdestroy.io