# PhishDestroy threat dossier — app-aster-dex.pages.dev ================================================================ Fetched: 2026-04-27 00:05:56 UTC Canonical: https://phishdestroy.io/domain/app-aster-dex.pages.dev/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 70/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/94 security vendors flagged this domain ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.66.47.202 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: Cloudflare, Inc. Nameservers: athena.ns.cloudflare.com, charles.ns.cloudflare.com Registered: 2026-04-24 Page title: 67,849.0 | BTCUSDT | Trade | Aster HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E8 Expires: 2026-07-20 Status: INVALID chain Fingerprint: 102cbd9e0aae03c9ba3b53484f48868d8a8130bef8e7395bc047b0b4ec29036f ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-24 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-24 22:44:30 UTC (by PhishDestroy tracker) Last verified: 2026-04-27 01:40:03 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019dc104-0adc-773c-ac2a-2d051577b4ae/ Wayback Machine: https://web.archive.org/web/*/app-aster-dex.pages.dev crt.sh CT logs: https://crt.sh/?q=%25.app-aster-dex.pages.dev Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=app-aster-dex.pages.dev AlienVault OTX: https://otx.alienvault.com/indicator/domain/app-aster-dex.pages.dev URLhaus: https://urlhaus.abuse.ch/host/app-aster-dex.pages.dev/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-24 22:46:06 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies app-aster-dex.pages.dev as an active generic phishing domain currently under investigation with an 'under_investigation' risk level. This domain masquerades as a legitimate service, likely deployed to harvest credentials or deliver malware through a deceptive user interface. The infrastructure is hosted on Cloudflare Pages using IP 172.66.47.202 and secured with a Let’s Encrypt SSL certificate. Despite zero detections on VirusTotal (0/95 engines), the absence of community or commercial blocklist inclusion does not confirm safety, particularly given the recent deployment and shallow reputation profile. This domain was flagged by PhishDestroy with indicators including VirusTotal detection ratio of 0/95, registration through Cloudflare, Inc., and resolution to IPv4 address 172.66.47.202. The phishing payload is served over HTTPS via a Let’s Encrypt certificate, which enhances perceived legitimacy while obfuscating malicious origin. As of seed 08697d, no public blocklists or threat intelligence platforms have flagged this domain, indicating it may be newly operational or using evasion tactics such as low-volume traffic or geographic targeting to delay detection. Mitigation requires immediate user avoidance and proactive blocking. Organizations should add app-aster-dex.pages.dev to DNS blocklists, email filters, and browser denylists due to its active phishing campaign posture. Users who may have interacted should change passwords on other services, enable two-factor authentication, and scan devices for compromise. Security teams should monitor outbound traffic to the IP 172.66.47.202 for signs of exfiltration or callback activity. Given the low detection environment but high operational risk, this domain poses a credible threat despite limited current visibility. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: ec46b6c8a59c8ed2d4cb0360950a0dfc TLS cert SHA-256: 102cbd9e0aae03c9ba3b53484f48868d8a8130bef8e7395bc047b0b4ec29036f ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/app-aster-dex.pages.dev/ JSON API: https://api.destroy.tools/v1/check?domain=app-aster-dex.pages.dev Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io