# PhishDestroy threat dossier — blocksrecovery.online ================================================================ Fetched: 2026-07-29 14:59:47 UTC Canonical: https://phishdestroy.io/domain/blocksrecovery.online/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 98/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Webroot Public blocklists: listed on 2 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 91.228.218.14 (UA, Kyiv) ASN: AS51264 Kutumova Olena Hosting org: Kutumova Olena Registrar: NAMECHEAP INC Nameservers: dns1.registrar-servers.com, dns2.registrar-servers.com Registered: 2026-07-14 Expires: 2027-07-14 Page title: Send USDT ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-14 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-29 08:10:14 UTC (by PhishDestroy tracker) First reported: 2026-07-29 06:21:53 UTC (abuse notice filed) Last verified: 2026-07-29 16:20:21 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fac8a-0b09-7758-ad65-19c5f3d1d704/ URLQuery: https://urlquery.net/report/195416c4-6bc1-49b4-9629-4013ebd00508 Wayback Machine: https://web.archive.org/web/*/blocksrecovery.online crt.sh CT logs: https://crt.sh/?q=%25.blocksrecovery.online Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=blocksrecovery.online AlienVault OTX: https://otx.alienvault.com/indicator/domain/blocksrecovery.online URLhaus: https://urlhaus.abuse.ch/host/blocksrecovery.online/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-29 08:12:24 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is blocksrecovery.online a phishing site? Analysis indicates that blocksrecovery.online is an active generic phishing domain first registered on July 14, 2026 through NAMECHEAP INC. The domain resolves to the IPv4 address 91.228.218.14 and is served by the authoritative nameservers dns1.registrar-servers.com and dns2.registrar-servers.com. Current intelligence shows the domain has been blocked by the PhishDestroy service and appears on a single external blocklist, confirming that at least one security community has taken mitigation action. VirusTotal scanning reports that two of ninety‑one security vendors have flagged the domain, providing additional corroboration of malicious intent. No further public indicators such as SSL certificate details, HTTP response codes, page titles, or brand targeting have been disclosed, leaving those aspects of the infrastructure unverified. Defenders should consider adding the IP address 91.228.218.14 and the domain blocksrecovery.online to network‑level deny lists, ensure that endpoint protection solutions are updated to reflect the two vendor detections, and monitor for any new sightings in threat‑intel feeds. Continuous observation of the registrar’s activity and periodic re‑query of blocklist status are recommended to capture potential changes in the domain’s operational posture. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260729-2FADFB Favicon MD5: e07f31545b76ce248776d930d696965a ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/blocksrecovery.online/ JSON API: https://api.destroy.tools/v1/check?domain=blocksrecovery.online Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,481 domains (83,248 alive under monitoring, 109,716 confirmed takedowns/dead). Site: https://phishdestroy.io