# PhishDestroy threat dossier — appstrt-dydax.wixstudio.com ================================================================ Fetched: 2026-06-27 09:46:41 UTC Canonical: https://phishdestroy.io/domain/appstrt-dydax.wixstudio.com/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 64/100 (PhishDestroy scoring — see methodology below) Targeted brand: dYdX ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 6/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Cluster25, Forcepoint ThreatSeeker, Gridinsoft, PREBYTES, Webroot Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- Registrar: GoDaddy.com, LLC Nameservers: ["dns1.p08.nsone.net", "dns2.p08.nsone.net", "dns3.p08.nsone.net", "dns4.p08.nsone.net"] Registered: 2026-06-08 Page title: dYdX™ || Swap Exchange®® ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-06-08 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-06-09 05:31:22 UTC (by PhishDestroy tracker) First reported: 2026-06-15 00:27:29 UTC (abuse notice filed) Last verified: 2026-06-27 08:20:34 UTC Neutralised: 2026-06-09 06:27:53 UTC Current status: taken down (registrar suspended or DNS dead) ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-26 01:34:14 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] This domain, appstrt-dydax.wixstudio.com, poses a direct financial threat by impersonating the dYdX cryptocurrency exchange platform. The site is designed to trick users into connecting their crypto wallets, enabling malicious smart contracts to drain funds without authorization. The page title, 'dYdX™ || Swap Exchange®®,' mimics official branding, while the underlying infrastructure—hosted on Wix Studio—leverages technologies like React and Google Cloud to appear legitimate. Users who interact with this site risk irreversible loss of digital assets, including Ethereum-based tokens and NFTs, through automated transaction hijacking scripts commonly associated with crypto drainer schemes. Analysis indicates this is a deliberately constructed phishing operation. The domain was registered on June 8, 2026, through GoDaddy.com, LLC, an unusually distant creation date suggesting potential domain spoofing or backdating. As of the latest scan, 6 out of 95 security vendors on VirusTotal flagged the domain as malicious, with detections from engines specializing in cryptocurrency threats. The site appears on three security blocklists, including PhishDestroy and PhishingArmy, and uses a Let’s Encrypt SSL certificate to feign legitimacy. Infrastructure analysis reveals the use of HSTS, HTTP/3, and Google Cloud CDN—technologies often employed to evade detection and improve phishing site performance. If you visited appstrt-dydax.wixstudio.com or connected a wallet to it, immediate action is required. First, revoke all active smart contract approvals associated with the connected wallet using a trusted blockchain explorer or security tool. Next, transfer remaining assets to a new, secure wallet address not previously exposed to the phishing site. Monitor all linked accounts for unauthorized transactions and enable transaction simulation tools to preview contract interactions before approval. Report the incident to the legitimate dYdX platform and relevant blockchain security teams to assist in tracking the threat. Avoid reusing passwords or wallet addresses from compromised sessions, as phishing operators often reuse infrastructure for follow-up attacks. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 9dae2d380288ac898efffb0f06444e23 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/appstrt-dydax.wixstudio.com/ JSON API: https://api.destroy.tools/v1/check?domain=appstrt-dydax.wixstudio.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 170,807 domains (12,466 alive under monitoring, 157,937 confirmed takedowns/dead). Site: https://phishdestroy.io