# PhishDestroy threat dossier — urlshort-linkmri0hvgk5adv.8go.workers.dev ================================================================ Fetched: 2026-07-29 19:57:13 UTC Canonical: https://phishdestroy.io/domain/urlshort-linkmri0hvgk5adv.8go.workers.dev/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: elster ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 6/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, ESET, G-Data, Gridinsoft, LevelBlue, Sophos Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 104.21.31.192 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: Cloudflare, Inc. Nameservers: NS_NOT_FOUND Page title: URL Kısaltıcı HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-10-10 Status: INVALID chain Fingerprint: f02a7960523c19ac15ca2f84d5ae4fd4d3ccffb70855433bc041c210ed1268ed Subject Alternative Names (related infrastructure — often same operator): - 8go.workers.dev ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-28 18:26:17 UTC (by PhishDestroy tracker) Last verified: 2026-07-29 21:34:07 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa9b4-432c-708e-8878-7ec1a75f1022/ Wayback Machine: https://web.archive.org/web/*/urlshort-linkmri0hvgk5adv.8go.workers.dev crt.sh CT logs: https://crt.sh/?q=%25.urlshort-linkmri0hvgk5adv.8go.workers.dev Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=urlshort-linkmri0hvgk5adv.8go.workers.dev AlienVault OTX: https://otx.alienvault.com/indicator/domain/urlshort-linkmri0hvgk5adv.8go.workers.dev URLhaus: https://urlhaus.abuse.ch/host/urlshort-linkmri0hvgk5adv.8go.workers.dev/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 18:30:36 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] urlshort-linkmri0hvgk5adv.8go.workers.dev: Phishing Site The domain urlshort-linkmri0hvgk5adv.8go.workers.dev is currently active and hosted on the IP address 172.67.179.154, which belongs to Cloudflare’s edge network. Registration information shows the domain was provisioned through Cloudflare, Inc., and no authoritative nameserver records are publicly available (NS_NOT_FOUND). VirusTotal analysis records six of ninety‑one scanning engines flagging the domain as malicious, indicating a modest but noteworthy detection rate. The site is listed on a single security blocklist and has been explicitly blocked by the PhishDestroy mitigation service, reinforcing its classification as a phishing vector. The intelligence source categorises the threat as generic phishing with a high risk rating. Evidence beyond the infrastructure signals is limited; page title, SSL certificate details, and content analysis have not been published in the current feed. Consequently, the exact phishing payload or targeted brand cannot be confirmed at this time. Defenders should treat the domain as hostile: network perimeter controls ought to deny outbound connections to the IP range, DNS filters should block the fully‑qualified domain name, and endpoint security solutions should enforce the VirusTotal detection verdict. Continuous monitoring for any new indicators, such as changes in payload delivery or additional blocklist entries, is recommended. Organizations that have observed traffic to this host should isolate affected systems and conduct forensic examination to determine whether credential harvesting or malware deployment occurred. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: f02a7960523c19ac15ca2f84d5ae4fd4d3ccffb70855433bc041c210ed1268ed ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/urlshort-linkmri0hvgk5adv.8go.workers.dev/ JSON API: https://api.destroy.tools/v1/check?domain=urlshort-linkmri0hvgk5adv.8go.workers.dev Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,504 domains (83,271 alive under monitoring, 109,716 confirmed takedowns/dead). Site: https://phishdestroy.io