# PhishDestroy threat dossier — simonefanclub.live ================================================================ Fetched: 2026-07-29 05:15:19 UTC Canonical: https://phishdestroy.io/domain/simonefanclub.live/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 98/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain AlienVault OTX: 4 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 103.224.212.101 (AU, Beaumaris) ASN: AS133618 Trellian Pty. Limited Hosting org: Trellian Pty. Limited Registrar: Global Domain Group LLC Nameservers: ["5772.ns1.abovedomains.com", "5772.ns2.abovedomains.com"] Page title: simonefanclub.live HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-10-10 Status: INVALID chain Fingerprint: ce83a50e710d9a57a8f2f8315f353d0e4a02be27da6566af52fc96be1edd5b85 Subject Alternative Names (related infrastructure — often same operator): - 5888mx004.com - 792147.com - 79t7.com - 7an.games - 849963.me - 90411b.com - 94132.top - 95248.my - 95hh.my - 967816.cc - 98231.my - 98395.loan - 98912.my - 98ga2x5m.news - 98yy.top ... +29 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-28 07:33:09 UTC (by PhishDestroy tracker) Last verified: 2026-07-29 04:20:26 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 07:34:14 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] simonefanclub.live: Confirmed Phishing Site Analysis of simonefanclub.live shows that the domain is actively responding with HTTP status 200, indicating that a live web service is present. The domain is registered through Global Domain Group LLC and resolves to the authoritative nameservers 5772.ns1.abovedomains.com and 5772.ns2.abovedomains.com, a configuration commonly observed for newly created malicious sites. VirusTotal records indicate that the domain has been scanned by 91 security vendors, and none have raised a detection at the time of review; this absence of flags should not be interpreted as evidence of benign behavior. The domain is listed on a single security blocklist and is explicitly blocked by the PhishDestroy service, confirming that at least one reputable anti‑phishing feed classifies it as malicious. No additional indicators such as SSL certificate details, IP geolocation, or associated malware kits are currently available in the public data set. The exact phishing campaign vector, targeted brand, and page content remain undocumented, leaving the specific lure technique uncertain. The lack of detections may stem from limited exposure, rapid takedown, or effective evasion techniques rather than inherent safety. Defensive operators should add simonefanclub.live to URL filtering and DNS blocklists, monitor outbound connections for attempts to resolve the domain, and enforce strict web‑proxy controls to prevent credential harvesting. Continuous re‑scanning with VirusTotal and other sandbox environments is recommended to capture any future malicious payloads that may appear. Sharing any observed indicators of compromise with industry threat‑sharing platforms will improve collective detection and mitigation capabilities. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: ce83a50e710d9a57a8f2f8315f353d0e4a02be27da6566af52fc96be1edd5b85 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/simonefanclub.live/ JSON API: https://api.destroy.tools/v1/check?domain=simonefanclub.live Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 192,591 domains (82,918 alive under monitoring, 107,787 confirmed takedowns/dead). Site: https://phishdestroy.io