# PhishDestroy threat dossier — binance-thirdparty.com ================================================================ Fetched: 2026-04-21 16:12:21 UTC Canonical: https://phishdestroy.io/domain/binance-thirdparty.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 82/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Binance ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/95 security vendors flagged this domain URLQuery: 2 detections ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 176.123.1.175 (MD, Chisinau) ASN: AS200019 ALEXHOST SRL Hosting org: Alexhost SRL Registrar: Fewmoretaps OU d/b/a Trustname.com !!! REGISTRAR INTEGRITY ALERT — Trustname / Fewmoretaps OU !!! Trustname (IANA #4318) is a shell company declaring EUR 120 annual revenue, 1 employee, negative equity, Belarusian ownership. Explicitly advertises itself as 'bulletproof' in its DNS TXT records. Primary source: https://phishdestroy.io/trustname-bulletproof-exposed Nameservers: ares.trustname.com, ns1.anycastdns.cz, ns2.anycastdns.cz, zeus.trustname.com Registered: 2026-04-11 Page title: 币安交易所 | 全球领先的加密货币交易平台 - 安全交易,瞬间致富 - 币安,您的数字资产首选 HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E8 Expires: 2026-07-10 Status: INVALID chain Fingerprint: 74585bcb52a5308f9ad4fa1c0d78c671ea4d7c9a54eceafbbe9ae0df5064af2e Subject Alternative Names (related infrastructure — often same operator): - www.binance-thirdparty.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-11 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-21 13:03:06 UTC (by PhishDestroy tracker) First reported: 2026-04-21 10:03:31 UTC (abuse notice filed) Last verified: 2026-04-21 18:12:05 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019daf7a-7aa8-737c-99e5-af1c5a39a8a8/ URLQuery: https://urlquery.net/report/3b75b413-5daf-43ad-aac3-d1f348ab8aa0 Wayback Machine: https://web.archive.org/web/*/binance-thirdparty.com crt.sh CT logs: https://crt.sh/?q=%25.binance-thirdparty.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=binance-thirdparty.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/binance-thirdparty.com URLhaus: https://urlhaus.abuse.ch/host/binance-thirdparty.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-21 13:04:22 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] The domain binance-thirdparty.com is currently identified as involved in brand impersonation specifically targeting the Binance cryptocurrency platform. This threat type aims to deceive users by mimicking the legitimate Binance brand to potentially harvest sensitive information or conduct fraudulent activities. At present, the domain's risk level remains under investigation, with the threat still active and ongoing. Technical analysis reveals that binance-thirdparty.com was registered on April 11, 2026, through the registrar Fewmoretaps OU operating under Trustname.com. The domain resolves to the IP address 176.123.1.175 and utilizes an SSL certificate issued by Let's Encrypt. Notably, VirusTotal scans report 0 detections out of 95 antivirus engines, indicating it has not yet been flagged by any major security vendors. No blocklist entries or negative trust scores have been confirmed at this time, though the domain's recent creation and brand impersonation nature warrant caution. Given the domain's active status and impersonation of the reputable Binance brand, users and security teams should exercise heightened vigilance. It is recommended to avoid engaging with this domain or submitting any credentials. Organizations should monitor for any suspicious activity linked to this IP and consider proactive blocking measures. Continued observation and further investigation are critical to determine the full extent of the threat posed by binance-thirdparty.com and to protect users from potential credential theft or fraud. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260421-2F159F Favicon MD5: a7c78c927f29f69f859e7bdb149c6aa0 TLS cert SHA-256: 74585bcb52a5308f9ad4fa1c0d78c671ea4d7c9a54eceafbbe9ae0df5064af2e ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/binance-thirdparty.com/ JSON API: https://api.destroy.tools/v1/check?domain=binance-thirdparty.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io