# PhishDestroy threat dossier — appmegaeth.com ================================================================ Fetched: 2026-05-20 14:15:51 UTC Canonical: https://phishdestroy.io/domain/appmegaeth.com/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: MetaMask ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/92 security vendors flagged this domain Public blocklists: listed on 2 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.67.206.125 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: MAT BAO CORPORATION Nameservers: ["adam.ns.cloudflare.com", "danica.ns.cloudflare.com"] Registered: 2026-05-08 Page title: MEGA | MegaETH HTTP response: 530 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E8 Expires: 2026-08-06 Status: INVALID chain Fingerprint: 069d4de71f9f92f8f46da47a8693b614e5317ef5add262853b958ddf663ddbfb ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-08 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-08 17:24:42 UTC (by PhishDestroy tracker) Earliest abuse rec: 2026-05-08 14:25:30 UTC — PREDATES current WHOIS registration; retained from a previous registration cycle of the same domain name Last verified: 2026-05-20 12:51:30 UTC Neutralised: 2026-05-09 23:14:19 UTC Current status: taken down (registrar suspended or DNS dead) Note: one or more events above predate the WHOIS creation date. This typically means the same domain name was previously registered, detected, dropped, and then re-registered by a new party. PhishDestroy preserves the full historical record for operator-attribution research even when the underlying infrastructure changes hands. ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e07f8-0661-7448-97d9-54d58e037aae/ URLQuery: https://urlquery.net/report/284c3660-3eef-4894-91b4-b8c68ea9d135 Wayback Machine: https://web.archive.org/web/*/appmegaeth.com crt.sh CT logs: https://crt.sh/?q=%25.appmegaeth.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=appmegaeth.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/appmegaeth.com URLhaus: https://urlhaus.abuse.ch/host/appmegaeth.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-08 17:26:02 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies appmegaeth.com as a live cryptocurrency wallet phishing domain impersonating MetaMask to steal seed phrases and private keys. This site was registered through MAT BAO CORPORATION on May 08, 2026 and already appears on 2 security blocklists. Despite resolving to IP 172.67.206.125 with a Let's Encrypt SSL certificate and receiving 0 detections on VirusTotal, MetaMask and SEAL have independently blocked access to the domain. This domain poses an immediate threat by tricking users into entering wallet credentials on a spoofed MetaMask interface. Attackers harvest entered seed phrases and private keys to drain cryptocurrency holdings from victims' wallets. The domain's recent creation date and low detection rate indicate it is actively used in campaigns, likely distributed via phishing emails, fake ads, or impersonation on social media platforms. If you visited appmegaeth.com, immediately disconnect any connected wallets, revoke any granted permissions, and transfer remaining funds to a new wallet using official applications only. Do not enter any credentials on this site. Scan your device for malware and consider rotating all wallet addresses and keys. Report the domain to your browser's blocklist and security vendors using the provided data: registrar MAT BAO CORPORATION, creation date May 08, 2026, IP 172.67.206.125, and VirusTotal results 0/95. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260508-E4DC57 Favicon MD5: bf57820134b35af7f4f02e9f1ba7cff8 TLS cert SHA-256: 069d4de71f9f92f8f46da47a8693b614e5317ef5add262853b958ddf663ddbfb ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/appmegaeth.com/ JSON API: https://api.destroy.tools/v1/check?domain=appmegaeth.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 152,024 domains (43,298 alive under monitoring, 108,446 confirmed takedowns/dead). Site: https://phishdestroy.io