# PhishDestroy threat dossier — bitmain.com.vc ================================================================ Fetched: 2026-07-27 20:34:25 UTC Canonical: https://phishdestroy.io/domain/bitmain.com.vc/ ## VERDICT ---------------------------------------------------------------- ACTIVE THREAT — multiple warning signs Composite threat score: 57/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 6/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, G-Data, Gridinsoft, Webroot AlienVault OTX: 1 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 217.196.54.189 (US, Phoenix) ASN: AS47583 Hostinger International Limited Hosting org: Hostinger International Limited Registrar: Key-Systems GmbH Nameservers: ns1.dns-parking.com, ns2.dns-parking.com Registered: 2024-10-03 Expires: 2027-10-03 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE2 Expires: 2026-09-26 Status: INVALID chain Fingerprint: a289d0f50608e5dfaff20eb693c96d0d4f495ff7be58365a7575ae0566160d75 Subject Alternative Names (related infrastructure — often same operator): - www.bitmain.com.vc ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2024-10-03 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 20:23:33 UTC (by PhishDestroy tracker) First reported: 2026-07-27 18:26:07 UTC (abuse notice filed) Last verified: 2026-07-27 22:00:27 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa4cf-898a-74d2-97f6-6352dfc1c0a4/ URLQuery: https://urlquery.net/report/a21af885-3816-4859-9ae6-e9f72a39ea11 Wayback Machine: https://web.archive.org/web/*/bitmain.com.vc crt.sh CT logs: https://crt.sh/?q=%25.bitmain.com.vc Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=bitmain.com.vc AlienVault OTX: https://otx.alienvault.com/indicator/domain/bitmain.com.vc URLhaus: https://urlhaus.abuse.ch/host/bitmain.com.vc/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 20:29:35 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] bitmain.com.vc Safety Check — Generic Phishing Detected Analysis of the domain bitmain.com.vc indicates that it is actively leveraged for a generic phishing campaign. The domain was registered on 03 October 2024 through Key-Systems GmbH and is hosted on an IP address (217.196.54.189) owned by Hostinger International Limited in the United States. DNS resolution is provided by the parking nameservers ns1.dns-parking.com and ns2.dns-parking.com, a configuration commonly observed in abuse infrastructure. VirusTotal has recorded detections from six of ninety‑one scanned security vendors, confirming that multiple independent scanners have flagged the host. The domain currently appears on one public blocklist and is listed as blocked by the PhishDestroy service, reinforcing its malicious status. The risk rating assigned is high and the operational status remains active as of the report date, 27 July 2026. Observable evidence therefore confirms that bitmain.com.vc is part of an ongoing phishing infrastructure. No additional data such as SSL certificate details, HTTP response codes, page titles, or brand targeting have been disclosed, leaving those aspects uncertain. Defenders should incorporate the IP address 217.196.54.189 and the domain name into network‑level deny lists, ensure that DNS resolvers block the associated parking nameservers, and monitor for any new detections from additional scanning engines. Continuous re‑evaluation is advised, as further threat intelligence may emerge. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-21441C Favicon MD5: 8eb0651f7c5f087e28c591c4e951308a TLS cert SHA-256: a289d0f50608e5dfaff20eb693c96d0d4f495ff7be58365a7575ae0566160d75 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/bitmain.com.vc/ JSON API: https://api.destroy.tools/v1/check?domain=bitmain.com.vc Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 207,230 domains (82,402 alive under monitoring, 123,797 confirmed takedowns/dead). Site: https://phishdestroy.io