# PhishDestroy threat dossier — webdisk.yenibet3.one ================================================================ Fetched: 2026-07-26 03:54:30 UTC Canonical: https://phishdestroy.io/domain/webdisk.yenibet3.one/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 56/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 10/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, BitDefender, Fortinet, G-Data, Kaspersky, LevelBlue, SOCRadar, Sophos, VIPRE, Webroot Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 209.42.19.29 (GB, London) ASN: AS51713 WHG Hosting Services Ltd Hosting org: WHG Hosting Services Ltd Registrar: Dynadot Inc Nameservers: ["ns3.mysecurecloudhost.com", "ns2.mysecurecloudhost.com", "ns4.mysecurecloudhost.com", "ns1.mysecurecloudhost.com"] HTTP response: 401 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-25 11:53:10 UTC (by PhishDestroy tracker) Last verified: 2026-07-26 04:20:22 UTC Neutralised: 2026-07-25 12:00:17 UTC Current status: taken down (registrar suspended or DNS dead) ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-25 11:54:19 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is webdisk.yenibet3.one a Scam? The domain webdisk.yenibet3.one is currently listed as an active generic phishing site with a high risk rating as of July 25, 2026. Registration data shows the domain was created through Dynadot Inc, indicating a commercial registrar often used for disposable or short‑lived infrastructure. VirusTotal analysis reveals that ten of ninety‑one security vendors have flagged the domain, providing a modest but notable consensus of malicious intent. The domain is present on a single external blocklist and is specifically blocked by the PhishDestroy service, reinforcing the view that security operators consider it abusive. HTTP monitoring reports a 302 temporary redirect response, a technique frequently employed to hide the final landing page or to route victims through intermediate stages before reaching a credential‑harvesting endpoint. Nameserver configuration lists ns3.mysecurecloudhost.com, ns2.mysecurecloudhost.com, and a partially truncated ns4.mysecurecloudhos, suggesting reliance on a cloud‑based DNS provider that may facilitate rapid changes to hosting parameters. No additional intelligence such as IP address, ASN, or SSL certificate details is available, leaving the underlying hosting environment uncertain. Given the confirmed detection counts, blocklist presence, and active redirect behavior, defenders should treat any traffic to webdisk.yenibet3.one as malicious. Recommended mitigations include adding the domain to network perimeter blocklists, configuring proxy or DNS filtering to deny resolution, and monitoring for any newly observed IP addresses that resolve to the listed nameservers. Continuous re‑evaluation is advised as the threat actor may alter the hosting stack or employ domain‑fronting techniques to evade static defenses. ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/webdisk.yenibet3.one/ JSON API: https://api.destroy.tools/v1/check?domain=webdisk.yenibet3.one Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,104 domains (64,738 alive under monitoring, 128,816 confirmed takedowns/dead). Site: https://phishdestroy.io