# PhishDestroy threat dossier — telogenltd.com ================================================================ Fetched: 2026-07-28 13:47:29 UTC Canonical: https://phishdestroy.io/domain/telogenltd.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 4/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, CRDF, Fortinet, Netcraft AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.97.3 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: CloudFlare, Inc. Registrar: Atak Domain Nameservers: igor.ns.cloudflare.com, zoe.ns.cloudflare.com Registered: 2024-01-17 Expires: 2027-01-17 Page title: telogenltd HTTP response: 301 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-09-04 Status: INVALID chain Fingerprint: 94c981557138e3ef50cca6caffa2a7b03db63c90f953bafecf4a29b15781423c ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2024-01-17 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 08:27:22 UTC (by PhishDestroy tracker) First reported: 2026-07-27 12:51:24 UTC (abuse notice filed) Last verified: 2026-07-28 12:54:58 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa2fd-d42c-7693-9f27-dc902232fe76/ URLQuery: https://urlquery.net/report/b213a38d-a846-429d-985d-4fd7b36fc1ca Wayback Machine: https://web.archive.org/web/*/telogenltd.com crt.sh CT logs: https://crt.sh/?q=%25.telogenltd.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=telogenltd.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/telogenltd.com URLhaus: https://urlhaus.abuse.ch/host/telogenltd.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 08:29:19 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] telogenltd.com Safety Check — Phishing Detected Analysis of telogenltd.com as of July 27 2026 indicates that the domain is currently active and has been classified as a generic phishing site. The domain was registered on 17 January 2024 through Atak Domain and is served by Cloudflare DNS (igor.ns.cloudflare.com, zoe.ns.cloudflare.com). DNS resolution points to the IPv4 address 188.114.97.3, an address that is commonly associated with hosting providers used for malicious campaigns. The domain appears on at least one security blocklist and is specifically blocked by the PhishDestroy filtering service, confirming that threat‑intelligence feeds have flagged it for phishing activity. VirusTotal scans have recorded four positive detections out of ninety‑one submitted security vendors, providing additional corroboration of malicious intent. The presence of multiple independent detections, combined with the blocklist entry, suggests a non‑trivial likelihood that the site is being used to harvest credentials or deliver fraudulent content. Open questions remain regarding the exact payload or lure employed by the site, as no public page title, SSL certificate details, or HTTP response codes have been disclosed. Consequently, the precise phishing vector cannot be confirmed at this time. Likewise, no information is available about the hosting provider’s ASN or the geographic location of the server beyond the IP address. Defensive recommendations include adding telogenltd.com to web‑filter deny lists, configuring email security gateways to block URLs that resolve to the domain, and monitoring network traffic for connections to 188.114.97.3. Organizations using threat‑intelligence platforms should ingest the blocklist indicator and the VirusTotal detection count to enrich existing detection rules. Continuous re‑evaluation is advised, as the domain’s activity status may change and additional indicators could emerge. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-D2D784 Favicon MD5: 1252239cdee04505706bc0035e9cfa4d TLS cert SHA-256: 94c981557138e3ef50cca6caffa2a7b03db63c90f953bafecf4a29b15781423c ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/telogenltd.com/ JSON API: https://api.destroy.tools/v1/check?domain=telogenltd.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 211,003 domains (85,443 alive under monitoring, 124,530 confirmed takedowns/dead). Site: https://phishdestroy.io