# PhishDestroy threat dossier — bitfinexinvest.co ================================================================ Fetched: 2026-07-27 05:27:18 UTC Canonical: https://phishdestroy.io/domain/bitfinexinvest.co/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 93/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 5/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, CRDF, Gridinsoft, Netcraft, PhishFort URLQuery: 2 detections Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 162.241.230.57 Registrar: Name.com, Inc. Nameservers: ns1.bluehost.com, ns2.bluehost.com Registered: 2023-01-02 Expires: 2027-01-02 Page title: BitFinexInvest - Home ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-10-07 Status: INVALID chain Fingerprint: fd078b1774b642efe53180a13d5a5b038989e2c0bc9c0dbe74af7e410b0e7d75 Subject Alternative Names (related infrastructure — often same operator): - autodiscover.bitfinexinvest.co - cpanel.bitfinexinvest.co - cpcalendars.bitfinexinvest.co - cpcontacts.bitfinexinvest.co - mail.bitfinexinvest.co - webdisk.bitfinexinvest.co - webmail.bitfinexinvest.co - www.bitfinexinvest.co ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2023-01-02 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 05:58:36 UTC (by PhishDestroy tracker) First reported: 2026-07-27 04:29:07 UTC (abuse notice filed) Last verified: 2026-07-27 06:50:21 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa1b7-a0be-749a-9f58-e988f0acb723/ URLQuery: https://urlquery.net/report/3b48fb40-db7f-42ce-b967-1c1a268f7a78 Wayback Machine: https://web.archive.org/web/*/bitfinexinvest.co crt.sh CT logs: https://crt.sh/?q=%25.bitfinexinvest.co Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=bitfinexinvest.co AlienVault OTX: https://otx.alienvault.com/indicator/domain/bitfinexinvest.co URLhaus: https://urlhaus.abuse.ch/host/bitfinexinvest.co/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 06:01:34 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] bitfinexinvest.co — Phishing Investigation Report This domain, bitfinexinvest.co, is currently active and has been classified as a generic phishing site. The registration record shows the domain was created on 2023-01-02 through Name.com, Inc., and its authoritative name servers are ns1.bluehost.com and ns2.bluehost.com. DNS resolution points to the IPv4 address 162.241.230.57. VirusTotal reports that five of ninety‑one scanned security vendors have flagged the domain, indicating a modest detection rate among scanners. The domain appears on a single public security blocklist and is explicitly blocked by the PhishDestroy service, reinforcing its malicious reputation. No additional public intelligence such as Safe Browsing or OTX entries is provided in the source data. Infrastructure analysis suggests the hosting provider is likely Bluehost, given the use of its name servers, but the specific hosting environment for the IP address is not detailed. The limited number of vendor detections and the single blocklist entry may reflect a relatively recent or low‑profile deployment, yet the presence of any detections confirms that security products have identified malicious behavior associated with the domain. The exact content served by the site, including page title or any SSL certificate details, has not been disclosed, leaving the precise phishing lure and target audience uncertain. Defenders should prioritize blocking traffic to 162.241.230.57 and adding bitfinexinvest.co to local deny lists. Monitoring for new detections from additional vendors or inclusion on further blocklists is advised, as the threat may evolve. Organizations that handle credentials related to financial services should be alerted to the possibility of credential‑harvesting attempts originating from this domain. Continuous observation of the domain’s DNS records and any changes to its hosting configuration is recommended to detect potential escalation. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-A75105 Favicon MD5: 64d37e8dbaee4fae92269324a57f8bd6 TLS cert SHA-256: fd078b1774b642efe53180a13d5a5b038989e2c0bc9c0dbe74af7e410b0e7d75 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/bitfinexinvest.co/ JSON API: https://api.destroy.tools/v1/check?domain=bitfinexinvest.co Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 202,849 domains (78,271 alive under monitoring, 123,547 confirmed takedowns/dead). Site: https://phishdestroy.io