# PhishDestroy threat dossier — stampbargain.com ================================================================ Fetched: 2026-04-21 21:25:03 UTC Canonical: https://phishdestroy.io/domain/stampbargain.com/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 60/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/95 security vendors flagged this domain ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 209.141.39.114 (US, Las Vegas) ASN: AS53667 FranTech Solutions Hosting org: FranTech Solutions Registrar: Fewmoretaps OU d/b/a Trustname.com !!! REGISTRAR INTEGRITY ALERT — Trustname / Fewmoretaps OU !!! Trustname (IANA #4318) is a shell company declaring EUR 120 annual revenue, 1 employee, negative equity, Belarusian ownership. Explicitly advertises itself as 'bulletproof' in its DNS TXT records. Primary source: https://phishdestroy.io/trustname-bulletproof-exposed Nameservers: ares.trustname.com, ns1.anycastdns.cz, ns2.anycastdns.cz, zeus.trustname.com Registered: 2026-03-25 Page title: Forever Stamps Store – Authorized Factory Outlet Online HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-06-21 Status: INVALID chain Fingerprint: dd11a9fc2db83dd462c37b462415116a353919eb9fbf33c35edbb47e9a650060 Subject Alternative Names (related infrastructure — often same operator): - www.stampbargain.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-03-25 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-21 07:02:12 UTC (by PhishDestroy tracker) Last verified: 2026-04-21 23:03:15 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019dae2f-6f92-737f-8aae-c835af442eb3/ Wayback Machine: https://web.archive.org/web/*/stampbargain.com crt.sh CT logs: https://crt.sh/?q=%25.stampbargain.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=stampbargain.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/stampbargain.com URLhaus: https://urlhaus.abuse.ch/host/stampbargain.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-21 07:03:57 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies stampbargain.com as an active threat currently under investigation for gift card phishing scams. The risk level is marked as under investigation due to ongoing analysis of the domain's intent and activity patterns. This domain specifically attempts to deceive victims by impersonating legitimate services to steal gift card information. Technical indicators reveal that stampbargain.com was registered on March 25, 2026, through Fewmoretaps OU operating as Trustname.com. It resolves to IP address 209.141.39.114 and uses a Let's Encrypt SSL certificate, which may provide a false sense of security to unsuspecting users. VirusTotal currently reports 0 detections out of 95 antivirus engines, indicating the domain has not yet been flagged by major security tools. There are no known blocklist entries at this time, which increases the risk of user exposure. The domain's recent creation date and registrar profile are consistent with tactics used by malicious actors to evade early detection. To mitigate risks associated with gift card phishing scams from stampbargain.com, users should avoid interacting with unsolicited emails or messages referencing this domain. Organizations should implement email filtering rules to block communications from this domain and monitor network traffic for connections to IP 209.141.39.114. Security teams are advised to educate users about the dangers of gift card scams and encourage verification of legitimate sources before providing any payment or card details. Continuous monitoring and updating of threat intelligence feeds will help detect emerging activity related to this domain. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: f9b61edbb38f15a71f20c5025193d3c4 TLS cert SHA-256: dd11a9fc2db83dd462c37b462415116a353919eb9fbf33c35edbb47e9a650060 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/stampbargain.com/ JSON API: https://api.destroy.tools/v1/check?domain=stampbargain.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io