# PhishDestroy threat dossier — 977776i.cleansite.info ================================================================ Fetched: 2026-05-31 07:49:32 UTC Canonical: https://phishdestroy.io/domain/977776i.cleansite.info/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: social_media Targeted brand: discord (and: facebook, instagram, twitter, youtube) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 23/95 security vendors flagged this domain Flagging vendors: ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CRDF, CyRadar, Ermes, ESET, Emsisoft, Forcepoint ThreatSeeker, Fortinet, G-Data, Google Safebrowsing, Gridinsoft, Kaspersky, Lionic, MalwareURL, Netcraft, Seclookup, Sophos, URLQuery, VIPRE, Webroot URLQuery: 100 detections Public blocklists: listed on 1 independent blocklist Google Safe Browsing: FLAGGED ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 57.131.27.32 (IT, Milan) ASN: ASAS16276 OVH OVH SAS, FR Hosting org: AS16276 OVH SAS Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com Nameservers: ns1.changeip.com, ns2.changeip.com, ns3.changeip.com, ns4.changeip.com, ns5.changeip.com Registered: 2018-03-06 Expires: 2026-06-07 Page title: PUBG MOBILE EVENT ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-03-15 Status: INVALID chain Fingerprint: beedd897af2aaf221208f924167a2f8fb3d2cac093b92d5571ba8c86f8769b17 Subject Alternative Names (related infrastructure — often same operator): - www.977776i.cleansite.info ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2018-03-06 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-02-25 02:39:27 UTC (by PhishDestroy tracker) First reported: 2025-12-16 13:33:45 UTC (abuse notice filed) Last verified: 2026-05-31 09:20:38 UTC Neutralised: 2026-03-15 06:13:50 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019b275d-70b6-70b9-907e-c09cf6d67661/ Wayback Machine: https://web.archive.org/web/*/977776i.cleansite.info crt.sh CT logs: https://crt.sh/?q=%25.977776i.cleansite.info Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=977776i.cleansite.info AlienVault OTX: https://otx.alienvault.com/indicator/domain/977776i.cleansite.info URLhaus: https://urlhaus.abuse.ch/host/977776i.cleansite.info/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-03-18 23:52:42 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies 977776i.cleansite.info as a high-risk brand impersonation domain targeting Discord users. The domain was associated with a deceptive page titled "PUBG MOBILE EVENT," attempting to lure victims through social engineering tactics under the guise of a popular gaming event. Technically, the domain was registered on March 6, 2018, via PDR Ltd. d/b/a PublicDomainRegistry.com and resolves to IP address 57.131.27.32. It has a very low trust score of 1/100 on Scamadviser and 0/100 on Gridinsoft, indicating high suspicion. Google Safe Browsing flagged it for social engineering, and it is listed on one security blocklist. VirusTotal analysis shows 23 out of 95 security vendors detect malicious activity, confirming its threat status. Currently, 977776i.cleansite.info is offline, reflecting prompt takedown efforts following identification. Users should remain vigilant for similar phishing campaigns impersonating Discord or other well-known brands. PhishDestroy recommends avoiding any contact with this domain and maintaining updated security measures to prevent exposure. [Updates since narrative was generated:] - VirusTotal detections: now 23/95 (narrative was written when count was lower) ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon SHA-256: dec3e9f0190a504ed0c8f4a5e957c107206ba106cac4a1bbb6cbac6369a16d56 TLS cert SHA-256: beedd897af2aaf221208f924167a2f8fb3d2cac093b92d5571ba8c86f8769b17 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/977776i.cleansite.info/ JSON API: https://api.destroy.tools/v1/check?domain=977776i.cleansite.info Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 156,171 domains (38,595 alive under monitoring, 117,071 confirmed takedowns/dead). Site: https://phishdestroy.io