# PhishDestroy threat dossier — test-fix.com ================================================================ Fetched: 2026-07-22 03:00:54 UTC Canonical: https://phishdestroy.io/domain/test-fix.com/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 75/100 (PhishDestroy scoring — see methodology below) Scam classification: Credential Phishing ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 5/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar AlienVault OTX: 4 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 46.38.226.119 (DE, Nuremberg) ASN: AS197540 netcup GmbH Hosting org: NETCUP-GMBH Registrar: IONOS SE Nameservers: ["ns1082.ui-dns.com", "ns1093.ui-dns.biz", "ns1095.ui-dns.de", "ns1112.ui-dns.org"] Registered: 2026-06-03 Expires: 2026-07-02 Page title: 403 Forbidden HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R13 Expires: 2026-04-01 Status: INVALID chain Fingerprint: d1c130ab3d794f66f6594c06a446ccf001ccd08ca6dc238e1b4d41ff7fda2431 Subject Alternative Names (related infrastructure — often same operator): - www.test-fix.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-06-03 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-06-09 05:23:23 UTC (by PhishDestroy tracker) First reported: 2026-06-15 06:46:41 UTC (abuse notice filed) Last verified: 2026-07-22 04:20:31 UTC Neutralised: 2026-06-16 00:42:09 UTC Current status: taken down (registrar suspended or DNS dead) ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-25 17:34:28 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] test-fix.com — Credential Harvesting Phishing Site Investigation This domain, test-fix.com, is identified as an active credential harvesting phishing site designed to deceive users into submitting sensitive authentication details, including usernames, passwords, and multi-factor authentication codes. Analysis indicates the site employs social engineering tactics such as impersonating legitimate login portals, often mimicking corporate or financial services to exploit user trust. The infrastructure is optimized for rapid deployment and evasion, with dynamic content delivery to bypass automated detection systems. Infrastructure analysis reveals concrete indicators of malicious activity. The domain is flagged by 5 out of 95 security vendors on a leading threat intelligence platform, while also appearing on one security blocklist. Registered on June 03, 2026, through a large-scale registrar, the domain resolves to the IP address 46.38.226.119, which has been associated with previous phishing campaigns. The SSL certificate, issued by a widely used public certificate authority, is valid and does not inherently indicate compromise, though its use in this context aligns with phishing infrastructure patterns. The domain remains actively hosted and accessible, increasing the risk of successful credential theft. Users who have visited test-fix.com or entered credentials on the site should take immediate remediation steps. All submitted credentials must be considered compromised and should be reset across all platforms where identical or similar passwords were used. Multi-factor authentication tokens associated with the accounts should also be revoked and reissued. Network-level blocking of the domain and its resolving IP address (46.38.226.119) is recommended for enterprise environments. Endpoint security tools should be updated to include this domain in real-time filtering rules, and affected users should be monitored for signs of unauthorized access or identity theft. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: d1c130ab3d794f66f6594c06a446ccf001ccd08ca6dc238e1b4d41ff7fda2431 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/test-fix.com/ JSON API: https://api.destroy.tools/v1/check?domain=test-fix.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 187,720 domains (57,297 alive under monitoring, 128,779 confirmed takedowns/dead). Site: https://phishdestroy.io