# PhishDestroy threat dossier — bt-cb-ul-lsto-ken.pages.dev ================================================================ Fetched: 2026-06-27 03:29:01 UTC Canonical: https://phishdestroy.io/domain/bt-cb-ul-lsto-ken.pages.dev/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Crypto Drainer Targeted brand: Bitcoin Phishing kit: Token Presale ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain Flagging vendors: Webroot Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.96.3 (US, San Francisco) ASN: ASAS13335 CLOUDFLARENET - Cloudflare, Inc., US Hosting org: AS13335 Cloudflare, Inc. Registrar: Cloudflare, Inc. Nameservers: elmo.ns.cloudflare.com, hera.ns.cloudflare.com Page title: BTC Bull Token | The Best Crypto Presale For Bitcoin Bulls HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-09-01 Status: INVALID chain Fingerprint: 7f7a618b76187bc79d419c59dd21c45836a6ea606f9fbe44405907eecc33af37 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-06-21 02:11:59 UTC (by PhishDestroy tracker) Last verified: 2026-06-27 04:20:35 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019ee784-1080-75ab-8cb2-1d8493a6b883/ Wayback Machine: https://web.archive.org/web/*/bt-cb-ul-lsto-ken.pages.dev crt.sh CT logs: https://crt.sh/?q=%25.bt-cb-ul-lsto-ken.pages.dev Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=bt-cb-ul-lsto-ken.pages.dev AlienVault OTX: https://otx.alienvault.com/indicator/domain/bt-cb-ul-lsto-ken.pages.dev URLhaus: https://urlhaus.abuse.ch/host/bt-cb-ul-lsto-ken.pages.dev/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-25 18:18:01 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] The domain bt-cb-ul-lsto-ken.pages.dev poses a significant threat as a crypto drainer, which is a type of phishing attack designed to steal cryptocurrency from unsuspecting users. These sites often masquerade as legitimate investment opportunities or presales, enticing victims to provide sensitive information or transfer funds under false pretenses. In this case, the page title claims to be related to a cryptocurrency presale, which heightens the risk of fraudulent behavior. The domain was registered through Cloudflare, Inc., and resolves to the IP address 188.114.96.3, located in the United States. Its SSL certificate is issued by Google Trust Services, indicating some level of security in communication, but this can mislead users into thinking the site is legitimate. The domain is currently active and has been flagged by one security blocklist, with a VirusTotal report showing 1 out of 95 security vendors marking it as suspicious. This indicates a low detection rate, suggesting that the domain may not be widely recognized as a threat yet. If an individual has visited bt-cb-ul-lsto-ken.pages.dev, it is crucial to take immediate action. Users should refrain from entering any personal or financial information on the site. It is advisable to monitor any connected cryptocurrency wallets for unauthorized transactions and consider changing passwords and enabling two-factor authentication on accounts that may have been exposed. Additionally, users should report the site to relevant authorities or cybersecurity platforms to help mitigate the threat to others. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 53dfbdf5fbaa534e1a0829fb270cf699 TLS cert SHA-256: 7f7a618b76187bc79d419c59dd21c45836a6ea606f9fbe44405907eecc33af37 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/bt-cb-ul-lsto-ken.pages.dev/ JSON API: https://api.destroy.tools/v1/check?domain=bt-cb-ul-lsto-ken.pages.dev Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 170,767 domains (12,435 alive under monitoring, 157,932 confirmed takedowns/dead). Site: https://phishdestroy.io