# PhishDestroy threat dossier — stage3.wpengine-flowpressousa.com ================================================================ Fetched: 2026-07-23 02:14:16 UTC Canonical: https://phishdestroy.io/domain/stage3.wpengine-flowpressousa.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 94/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 3/91 security vendors flagged this domain Flagging vendors: CRDF, Gridinsoft, SOCRadar Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 103.101.85.123 (RU, Moscow) ASN: AS207567 Intezio Worldwide Limited Hosting org: IP Melnikov Ilya Pavlovich Registrar: MAT BAO CORPORATION Nameservers: gene.ns.cloudflare.com, otto.ns.cloudflare.com Registered: 2026-06-17 Expires: 2027-06-17 Page title: Discovery Call HTTP response: 301 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-09-19 Status: INVALID chain Fingerprint: 10c79e4bd4f5209833a019ba81406bfd416700e4088e1e186d7faaf7891a438c Subject Alternative Names (related infrastructure — often same operator): - stage3.wpengine-bestbidestimating.com - stage3.wpengine-myfloraland.com - stage3.wpengine-tagtogs.com - stage3.wpengine-tennisintheparks.com - stage3.wpengine-universalimaginginc.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-06-17 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-22 23:40:27 UTC (by PhishDestroy tracker) First reported: 2026-07-22 21:46:18 UTC (abuse notice filed) Last verified: 2026-07-23 00:50:11 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f8bc4-f122-76b0-917f-4659d195bcda/ URLQuery: https://urlquery.net/report/a8fb8277-02a1-4712-82f2-6f37fc23ca20 Wayback Machine: https://web.archive.org/web/*/stage3.wpengine-flowpressousa.com crt.sh CT logs: https://crt.sh/?q=%25.stage3.wpengine-flowpressousa.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=stage3.wpengine-flowpressousa.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/stage3.wpengine-flowpressousa.com URLhaus: https://urlhaus.abuse.ch/host/stage3.wpengine-flowpressousa.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-22 23:41:49 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] stage3.wpengine-flowpressousa.com phishing site impersonates Analysis of the domain stage3.wpengine-flowpressousa.com indicates active phishing infrastructure targeting users of web hosting or content management services. The domain was registered on June 17, 2026, through MAT BAO CORPORATION, a registrar previously associated with abusive registrations. It currently resolves to the IP address 103.101.85.123, which has been observed in prior malicious campaigns. Nameservers gene.ns.cloudflare.com and otto.ns.cloudflare.com suggest the use of Cloudflare services, a common tactic to obscure hosting origins and evade takedowns. Detection data remains limited but indicative of malicious intent. As of July 22, 2026, the domain is flagged by one security blocklist and has been identified by 3 of 95 security vendors on VirusTotal, though the specific detection rules or signatures are not disclosed. The domain is also blocked by PhishDestroy, a specialized anti-phishing service. No further details regarding the brand impersonated, page content, or phishing kit are available at this time, as the site has not undergone full content analysis. Defenders should treat this domain as high-risk based on its registration context, hosting infrastructure, and early detection by security vendors. Immediate actions include blocking the domain and its resolving IP at the network perimeter, monitoring for connections to 103.101.85.123, and reviewing logs for any prior interactions. Given the use of Cloudflare, additional scrutiny of related subdomains or domains sharing the same nameservers may be warranted. The domain remains active, and further monitoring is recommended to assess its evolution or potential expansion into additional campaigns. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260722-5BC272 Favicon MD5: b1505175dfb013552361a3cce3afb90e TLS cert SHA-256: 10c79e4bd4f5209833a019ba81406bfd416700e4088e1e186d7faaf7891a438c ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/stage3.wpengine-flowpressousa.com/ JSON API: https://api.destroy.tools/v1/check?domain=stage3.wpengine-flowpressousa.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 188,586 domains (58,700 alive under monitoring, 128,261 confirmed takedowns/dead). Site: https://phishdestroy.io