# PhishDestroy threat dossier — 998xpj15.top ================================================================ Fetched: 2026-07-23 13:04:47 UTC Canonical: https://phishdestroy.io/domain/998xpj15.top/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 83/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/91 security vendors flagged this domain Flagging vendors: Fortinet, Seclookup Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 103.224.212.104 (AU, Beaumaris) ASN: AS133618 Trellian Pty. Limited Hosting org: Trellian Pty. Limited Registrar: Dynadot LLC Nameservers: ["5014.ns1.abovedomains.com.", "5014.ns2.abovedomains.com."] Page title: 998xpj15.top HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-10-10 Status: INVALID chain Fingerprint: d606146be9ca84d6dbba5e231aa06c3a3213e52711a3a66d442e62d0158e225e Subject Alternative Names (related infrastructure — often same operator): - 06264.army - 071201.academy - 10021.gdn - 11215.cc - 11271.cc - 11351.cc - 1rg12gji6hjkhaz.top - 465274.lol - 465474.lol - 619185.lol - 619343.com - 639270.lol - 63b58badf5e21379.com - 689780.lol - 987121.vip ... +27 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-19 13:01:30 UTC (by PhishDestroy tracker) Last verified: 2026-07-23 12:22:36 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-19 13:08:24 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] 998xpj15.top Safety Check — Phishing Detected The domain 998xpj15.top is currently classified as an active phishing threat. As of July 19, 2026, it maintains an HTTP status of 200, indicating that the site is operational. Analysis shows that this domain is flagged by 2 out of 95 security vendors, suggesting a moderate level of concern among security tools, although the majority do not yet detect it as a threat. Additionally, it is listed on one security blocklist and has been specifically blocked by PhishDestroy. This information points to the potential for malicious activity linked to this domain, though specific details on the nature of the phishing or any targeted entities remain unverified at this time. Defenders are advised to monitor network traffic for any interactions with this domain and implement blocks where possible to mitigate risks associated with phishing attempts. Continuous updates from security vendors and blocklists should be monitored to enable timely responses to evolving threats. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: d606146be9ca84d6dbba5e231aa06c3a3213e52711a3a66d442e62d0158e225e ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/998xpj15.top/ JSON API: https://api.destroy.tools/v1/check?domain=998xpj15.top Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 188,735 domains (58,384 alive under monitoring, 128,729 confirmed takedowns/dead). Site: https://phishdestroy.io