# PhishDestroy threat dossier — 61395.xyz ================================================================ Fetched: 2026-07-28 20:11:16 UTC Canonical: https://phishdestroy.io/domain/61395.xyz/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 16/91 security vendors flagged this domain Flagging vendors: Criminal IP, alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Kaspersky, Lionic, SOCRadar, Sophos, VIPRE, Webroot Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 103.27.177.164 (HK, Mong Kok) ASN: AS135357 HONG KONG KOWLOON TELECOMMUNICATIONS CO.,LIMITED Hosting org: HONG KONG KOWLOON TELECOMMUNICATIONS CO., LIMITED Registrar: Gname.com Pte. Ltd. Nameservers: ["a5.share-dns.com", "b5.share-dns.net"] ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-09-14 Status: INVALID chain Fingerprint: 244bbf1506449b972dad555a38ef3d1d082e13afc6e740a792ffc49b9338d48c Subject Alternative Names (related infrastructure — often same operator): - 61257.xyz - 61259.xyz - 61270.xyz - 61330.xyz - 61370.xyz - 61373.xyz - 61378.xyz - 61381.xyz - 61384.xyz - 61385.xyz - 61393.xyz - 61400.xyz - 61401.xyz - 61403.xyz - 61415.xyz ... +82 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-19 13:01:21 UTC (by PhishDestroy tracker) Last verified: 2026-07-28 16:20:29 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-22 14:03:19 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] 61395.xyz phishing site impersonates brands via Cloudflare proxy Analysis of the domain 61395.xyz indicates it is an active phishing infrastructure currently under investigation. Registered through Gname.com Pte. Ltd., the domain resolves to IP address 103.27.177.164, hosted by Hong Kong Kowloon Telecommunications Co., Limited. Nameservers a5.share-dns.com and b5.share-dns.net are configured, and the site employs Cloudflare as a reverse proxy, which may obscure direct server analysis. HTTP/3 and HSTS headers are present, alongside Vue.js and Nginx, suggesting a modern frontend framework and web server deployment. The SSL certificate is issued by Let's Encrypt (YR1), valid as of the report date. The domain appears on one security blocklist, specifically PhishDestroy, which has flagged it for phishing activity. No detections were recorded by the 91 vendors that scanned the domain on VirusTotal, though this absence does not confirm safety. The exact nature of the phishing content remains unconfirmed, as the page title and targeted brand have not been analyzed. Infrastructure analysis reveals the use of Cloudflare, which may complicate IP-based blocking and attribution efforts. Defenders are advised to monitor traffic to 61395.xyz, particularly any HTTP requests or DNS queries originating from internal networks. Given the domain's presence on a blocklist and its hosting in a region frequently associated with phishing operations, organizations should consider preemptive blocking at the DNS or proxy level. Further analysis of captured network traffic or endpoint telemetry may provide additional indicators of compromise, such as specific paths, query parameters, or POST requests associated with credential harvesting or malware delivery. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: 244bbf1506449b972dad555a38ef3d1d082e13afc6e740a792ffc49b9338d48c ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/61395.xyz/ JSON API: https://api.destroy.tools/v1/check?domain=61395.xyz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 208,133 domains (82,872 alive under monitoring, 124,229 confirmed takedowns/dead). Site: https://phishdestroy.io