# PhishDestroy threat dossier — ticketsgem.com ================================================================ Fetched: 2026-07-30 09:50:03 UTC Canonical: https://phishdestroy.io/domain/ticketsgem.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 88/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 165.245.219.4 (DE, Frankfurt am Main) ASN: AS14061 DigitalOcean, LLC Hosting org: DigitalOcean, LLC Registrar: HOSTINGER operations, UAB Nameservers: ["clayton.ns.cloudflare.com", "grace.ns.cloudflare.com"] Page title: Grand Egyptian Museum Ticket HTTP response: 301 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE2 Expires: 2026-09-23 Status: INVALID chain Fingerprint: ee4f5e186605245846804d2a8e32ec79dfc707fb0dc1a87da684b2fd1f2acd15 Subject Alternative Names (related infrastructure — often same operator): - chateauversaillesticket.com - egypt-monuments.com - france-monuments.com - lelouvrebillet.com - sge.chateauversaillesticket.com - sge.egypt-monuments.com - sge.france-monuments.com - sge.lelouvrebillet.com - sge.thailand-monuments.com - sge.thelondoneyetickets.com - sge.tickets-grandegyptianmuseum.com - sge.ticketsgem.com - sge.tivoligardenstickets.com - sge.uffizigalleries.com - thailand-monuments.com ... +15 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-28 17:03:09 UTC (by PhishDestroy tracker) Last verified: 2026-07-30 09:34:06 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 17:04:23 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] ticketsgem.com used in active generic phishing campaign Analysis indicates that the domain ticketsgem.com remains active as of the report date, July 28 2026. Registration records show the domain was created through Hostinger operations, UAB, and the authoritative nameservers are listed as clayton.ns.cloudflare.com and grace.ns.cloudflare.com, indicating use of Cloudflare’s DNS service. An HTTP request to the domain returns a 301 status code, suggesting a permanent redirect to another location, though the target URL has not been disclosed in the available intelligence. The domain has been flagged by the PhishDestroy mitigation service and appears on one external security blocklist, providing at least a minimal level of community‑derived detection. VirusTotal analysis reports that the site was examined by 91 antivirus and URL‑reputation vendors, and none of those scanners generated a detection at the time of scanning. The absence of detections does not constitute confirmation of benign behavior, but it does reflect that the payload or landing page did not match signatures in the current vendor databases. Safe Browsing data is not present in the current feed, and no Open Threat Exchange (OTX) entries have been published for this fully qualified domain name. No SSL certificate details, page title, or brand targeting are currently available, limiting the ability to attribute the campaign to a specific brand or to assess visual mimicry. Given the limited public evidence, defenders should treat ticketsgem.com as a high‑confidence phishing indicator. Recommended actions include adding the domain to local and network‑level blocklists, monitoring DNS queries for the associated Cloudflare nameservers, and employing URL filtering solutions that reference community blocklists such as PhishDestroy. Continuous re‑scanning with multi‑vendor services is advisable to capture any future changes in the payload or hosting configuration. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: b6137784a40d3dd2d0d65297c44930e6 TLS cert SHA-256: ee4f5e186605245846804d2a8e32ec79dfc707fb0dc1a87da684b2fd1f2acd15 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/ticketsgem.com/ JSON API: https://api.destroy.tools/v1/check?domain=ticketsgem.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,592 domains (93,417 alive under monitoring, 99,913 confirmed takedowns/dead). Site: https://phishdestroy.io