# PhishDestroy threat dossier — assets-cakeswap.xyz ================================================================ Fetched: 2026-06-29 09:20:01 UTC Canonical: https://phishdestroy.io/domain/assets-cakeswap.xyz/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: PancakeSwap ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 5/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet, PhishFort, SOCRadar Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 45.154.98.50 (NL, Lelystad) ASN: ASAS210558 services-1337-gmbh 1337 Services GmbH, DE Hosting org: AS210558 1337 Services GmbH Registrar: TLD Registrar Solutions Ltd. Nameservers: ns1.rdp.sh, ns2.rdp.rs Registered: 2026-06-17 Expires: 2027-06-17 Page title: Assets CakeSwap — PancakeSwap Asset Hub HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE1 Expires: 2026-09-15 Status: INVALID chain Fingerprint: e45b3e4dff53ea55398714e5a7ae4ef2f86097ee50b9be2064f084c846643a91 Subject Alternative Names (related infrastructure — often same operator): - api.assets-cakeswap.xyz - www.assets-cakeswap.xyz ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-06-17 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-06-19 09:18:12 UTC (by PhishDestroy tracker) First reported: 2026-06-19 07:22:34 UTC (abuse notice filed) Last verified: 2026-06-29 08:20:35 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019edebd-c809-7258-b09e-d419e33063d5/ URLQuery: https://urlquery.net/report/406b9155-5b13-482e-bc08-3c718a15f640 Wayback Machine: https://web.archive.org/web/*/assets-cakeswap.xyz crt.sh CT logs: https://crt.sh/?q=%25.assets-cakeswap.xyz Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=assets-cakeswap.xyz AlienVault OTX: https://otx.alienvault.com/indicator/domain/assets-cakeswap.xyz URLhaus: https://urlhaus.abuse.ch/host/assets-cakeswap.xyz/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-22 23:04:55 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] The domain assets-cakeswap.xyz is flagged for crypto phishing by multiple security vendors. Five out of 91 VirusTotal vendors identify it as malicious, and it appears on public blocklists from PhishDestroy, MetaMask, and SEAL. Despite its current parked status, the domain's association with cryptocurrency scams is concerning. Registered through TLD Registrar Solutions Ltd. and hosted on an IP in the Netherlands by 1337 Services GmbH, assets-cakeswap.xyz presents a high platform risk score of 90 out of 100. Its SSL certificate is issued by Let's Encrypt, a common choice for malicious actors due to its ease of access and cost-free nature. The domain's abuse score is relatively low at 21 out of 100, which might indicate limited complaints so far. The domain was created on June 17, 2026, and PhishDestroy detected it two days later. This quick identification highlights the efficiency of PhishDestroy's threat intelligence pipeline in catching threats early. The domain's presence on multiple blocklists and its VirusTotal detection count suggest it has been used in attempts to deceive users, likely targeting those involved in cryptocurrency transactions. The parked status may indicate a temporary pause in activity, but the threat remains significant given its previous malicious use. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260619-E2CF45 TLS cert SHA-256: e45b3e4dff53ea55398714e5a7ae4ef2f86097ee50b9be2064f084c846643a91 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/assets-cakeswap.xyz/ JSON API: https://api.destroy.tools/v1/check?domain=assets-cakeswap.xyz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 172,428 domains (13,714 alive under monitoring, 158,147 confirmed takedowns/dead). Site: https://phishdestroy.io