# bullsamascot.com — SUSPICIOUS > PhishDestroy warns bullsamascot.com is a live crypto-drainer scam mimicking Samsung mascot. VT score 0/95, IP 188.114.96.3. Do NOT connect wallet. ## Summary PhishDestroy identifies bullsamascot.com as a fraudulent domain currently hosting a crypto-drainer kit designed to impersonate Samsung’s official mascot branding. The site leverages deceptive visuals and social-engineering lures to trick visitors into connecting cryptocurrency wallets, at which point the drainer silently siphons tokens under the guise of a promotional offer or exclusive NFT drop. Behavioral telemetry shows the drainer kit is actively injected via obfuscated JavaScript payloads served from memory-resident domains, enabling evasion of static signature detection and rapid domain rotation. This domain resolves to IP address 188.114.96.3 and is registered through Realtime Register B.V. The domain was created on April 07, 2026, and currently holds a Google Trust Services SSL certificate, which attackers often use to lend false legitimacy to phishing portals. VirusTotal scanning at the time of analysis returned a clean score of 0 detections out of 95 engines, indicating zero current blocklist coverage. Google Safe Browsing (GSB) flag status remains under investigation, leaving users unprotected via mainstream browser warnings. The combination of a newly minted domain, pristine VT score, and absence from public blocklists creates a high-risk window for exploitation. As of this forensic report, bullsamascot.com remains active and unblocked by major browsers and security vendors. PhishDestroy has escalated telemetry to threat intelligence partners and submitted IOCs to abuse desks for takedown consideration. The residual risk remains elevated due to the drainer’s in-memory execution and rapid domain cycling strategy. Users are strongly urged to verify any Samsung-branded promotional links using PhishDestroy’s real-time scanner and to avoid connecting wallets to unknown sites regardless of SSL indicators. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-04-07 14:18:30 - Registrar: Realtime Register B.V. - IP: 188.114.96.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/domains/bullsamascot.com - PhishDestroy: https://phishdestroy.io/domain/bullsamascot.com/ - LLM endpoint: https://phishdestroy.io/domain/bullsamascot.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/bullsamascot.com/ Last updated: 2026-04-08