# PhishDestroy threat dossier — wffqs.com ================================================================ Fetched: 2026-07-26 07:57:19 UTC Canonical: https://phishdestroy.io/domain/wffqs.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 20/93 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, Cluster25, CRDF, CyRadar, DNS8, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Google Safebrowsing, Gridinsoft, Kaspersky, Lionic, Seclookup, SOCRadar, Sophos, VIPRE, Webroot AlienVault OTX: 1 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist Google Safe Browsing: FLAGGED ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 91.202.233.156 (RU, Saint Petersburg) ASN: ASAS200593 PROSPERO-AS PROSPERO OOO, RU Hosting org: AS200593 PROSPERO OOO Registrar: Dynadot LLC Nameservers: ["a.dnspod.com", "b.dnspod.com"] Registered: 2026-02-21 Page title: 邮箱企业 | User: HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: none Expires: 2030-05-31 Status: INVALID chain ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-02-21 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-02-26 23:23:04 UTC (by PhishDestroy tracker) First reported: 2026-02-26 23:23:04 UTC (abuse notice filed) Last verified: 2026-07-26 08:21:09 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019bc125-1b42-74e9-9854-777481b9d9d3/ URLQuery: https://urlquery.net/report/31a459e3-5f00-4f63-825e-deb960c566ce Wayback Machine: https://web.archive.org/web/*/wffqs.com crt.sh CT logs: https://crt.sh/?q=%25.wffqs.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=wffqs.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/wffqs.com URLhaus: https://urlhaus.abuse.ch/host/wffqs.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-25 21:21:20 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] wffqs.com: Fake Email Login Portal Phishing for Credentials This domain, wffqs.com, is identified as a high-risk phishing site targeting enterprise email credentials. Analysis of the page title, 邮箱企业 | User:, indicates an attempt to impersonate corporate email login portals, likely to harvest credentials for unauthorized access or further phishing campaigns. No specific brand impersonation or cryptocurrency drainer kit signatures were detected, but the generic phishing framework suggests broad targeting of business users. Infrastructure analysis reveals the following technical indicators: VirusTotal detection score of 20/95 security vendors flagging the domain as malicious, registered through Dynadot LLC on February 21, 2026. The domain resolves to IP address 91.202.233.156, hosted in Russia under AS200593 (PROSPERO OOO). Google Safe Browsing explicitly flags this domain as phishing, and it appears on three security blocklists. The absence of an SSL certificate further reduces legitimacy, increasing the likelihood of credential interception in plaintext. As of the latest assessment, wffqs.com has been taken offline, mitigating immediate user exposure. However, the domain remains registered and could be reactivated or repurposed. Organizations are advised to block the domain and associated IP at perimeter security controls. Users who may have interacted with the site should reset credentials via secure channels and monitor accounts for unauthorized activity. The creation date discrepancy (2026) suggests domain age manipulation, a common tactic to evade detection during initial deployment. [Updates since narrative was generated:] - VirusTotal detections: now 20/93 (narrative was written when count was lower) ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/wffqs.com/ JSON API: https://api.destroy.tools/v1/check?domain=wffqs.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 196,105 domains (65,739 alive under monitoring, 128,816 confirmed takedowns/dead). Site: https://phishdestroy.io