# PhishDestroy threat dossier — verbotech.net ================================================================ Fetched: 2026-07-28 11:09:25 UTC Canonical: https://phishdestroy.io/domain/verbotech.net/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 9/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, BitDefender, CRDF, Fortinet, G-Data, Kaspersky, Lionic, Netcraft, Sophos AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 51.222.162.110 (CA, Beauharnois) ASN: AS16276 OVH SAS Hosting org: Securelayer, Network Registrar: HOSTINGER operations, UAB Nameservers: ns5.ddoscure.com, ns6.ddoscure.com, protected3.ddoscure.com, protected4.ddoscure.com Registered: 2024-09-13 Expires: 2026-09-13 Page title: verbotech.net ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-09-02 Status: INVALID chain Fingerprint: 44730eae3e8ff17e3a5e81c4658762c1b0c513624956153b0c3897de44b720dd ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2024-09-13 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 09:01:04 UTC (by PhishDestroy tracker) First reported: 2026-07-27 13:29:00 UTC (abuse notice filed) Last verified: 2026-07-28 12:54:26 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa312-324a-777c-a2e0-8906094cae53/ URLQuery: https://urlquery.net/report/fe38ee9c-f57c-4fc5-a7b1-f91593bdad6d Wayback Machine: https://web.archive.org/web/*/verbotech.net crt.sh CT logs: https://crt.sh/?q=%25.verbotech.net Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=verbotech.net AlienVault OTX: https://otx.alienvault.com/indicator/domain/verbotech.net URLhaus: https://urlhaus.abuse.ch/host/verbotech.net/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 09:01:17 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] verbotech.net — Generic Phishing Infrastructure Report verbotech.net is currently listed on a security blocklist and is actively flagged by the PhishDestroy sinkhole. The domain resolves to the IPv4 address 51.222.162.110, which is the sole host observed for this indicator. Registration data shows the domain was created on 13 September 2024 through Hostinger Operations, UAB, and is delegated to the nameservers ns5.ddoscure.com, ns6.ddoscure.com, protected3.ddoscure.com, and protected4.ddoscure.co. VirusTotal analysis records nine of ninety‑one antivirus and URL‑reputation engines marking the domain as malicious, reinforcing the blocklist findings. No public SSL certificate, HTTP status code, or page title information is presently available, limiting visibility into the payload or landing page content. The lack of additional infrastructure such as secondary IPs, CDN usage, or known phishing kit signatures suggests a relatively simple deployment, but the presence of multiple ddoscure‑controlled nameservers indicates purposeful attempts to obscure ownership. Defenders should continue to block verbotech.net at network perimeters, update URL filtering lists, and monitor outbound connections to 51.222.162.110 for potential data exfiltration. Further investigation, including a safe‑browse request to capture the landing page HTML and any associated redirects, would clarify the exact phishing lure and enable more precise detection signatures. Until such analysis is performed, the domain remains a high‑risk indicator of ongoing generic phishing campaigns. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-F7EE37 Favicon MD5: 43a5c32dd995dcd9bf52fcf675938e98 TLS cert SHA-256: 44730eae3e8ff17e3a5e81c4658762c1b0c513624956153b0c3897de44b720dd ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/verbotech.net/ JSON API: https://api.destroy.tools/v1/check?domain=verbotech.net Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 210,393 domains (84,854 alive under monitoring, 124,509 confirmed takedowns/dead). Site: https://phishdestroy.io