# PhishDestroy threat dossier — autoproftrade.com ================================================================ Fetched: 2026-04-21 21:14:41 UTC Canonical: https://phishdestroy.io/domain/autoproftrade.com/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 75/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 14/95 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar, ESET, Fortinet, G-Data, Google Safebrowsing, Lionic, Netcraft, Sophos, VIPRE URLQuery: 2 detections Public blocklists: listed on 1 independent blocklist Google Safe Browsing: FLAGGED ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 163.61.188.7 (US, Staten Island) ASN: AS153568 NEW DHAKA HARDWARE Hosting org: MIT Registrar: Atak Domain Nameservers: dns1.lytehosting.com, dns2.lytehosting.com, dns3.lytehosting.com, dns4.lytehosting.com, ns1.cprapid.com, ns2.cprapid.com Registered: 2025-11-26 Page title: Auto Proftrade HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-06-26 Status: INVALID chain Fingerprint: 8298303e7cea9024a279b9f0ee391ec16f8b095503c57a6197471b7844c7e443 Subject Alternative Names (related infrastructure — often same operator): - mail.autoproftrade.com - www.autoproftrade.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-11-26 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-21 20:56:29 UTC (by PhishDestroy tracker) First reported: 2026-04-21 17:57:04 UTC (abuse notice filed) Last verified: 2026-04-21 23:15:06 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019db12d-6c97-7079-93d0-3f184dbc0d13/ URLQuery: https://urlquery.net/report/01cfd909-db1d-4203-8348-94194aa91c5d Wayback Machine: https://web.archive.org/web/*/autoproftrade.com crt.sh CT logs: https://crt.sh/?q=%25.autoproftrade.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=autoproftrade.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/autoproftrade.com URLhaus: https://urlhaus.abuse.ch/host/autoproftrade.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-21 20:57:07 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] autoproftrade.com is an active crypto drainer phishing domain posing a high-risk threat to cryptocurrency holders. This domain mimics legitimate trading platforms to trick users into connecting wallets and authorizing malicious token approvals. The attackers leverage urgency and fake trading incentives to deceive victims into draining their crypto holdings, making this a critical threat to digital asset security. This domain was flagged by PhishDestroy following analysis of multiple threat intelligence sources. VirusTotal detects confirmed the presence of malicious activity with 14 out of 95 security vendors marking the domain as harmful. The domain resolves to IP 163.61.188.7 and uses a Let's Encrypt SSL certificate for added deception. Registered through Atak Domain on November 26, 2025, autoproftrade.com has already been blacklisted by InversionDNS and flagged by Google Safe Browsing under SOCIAL_ENGINEERING categories. The domain’s recent creation and rapid blacklisting indicate opportunistic malicious deployment targeting unsuspecting users. To mitigate risk, users must avoid interacting with autoproftrade.com entirely. If this domain was accessed, disconnect wallets immediately and revoke any unauthorized token approvals through blockchain explorers or wallet interfaces. Report the domain to your security provider and relevant crypto communities to prevent further exposure. Always verify URLs, use hardware wallets for sensitive transactions, and enable transaction confirmation features that allow risk assessment before approvals. Monitor blockchain transaction logs for unauthorized transfers and consider using wallet protection tools that alert users to suspicious token approval requests. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260421-DCE7C5 Favicon MD5: 48df13183ab0a07bbd1c274da11fff20 TLS cert SHA-256: 8298303e7cea9024a279b9f0ee391ec16f8b095503c57a6197471b7844c7e443 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/autoproftrade.com/ JSON API: https://api.destroy.tools/v1/check?domain=autoproftrade.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io