# PhishDestroy threat dossier — bxxn.netlify.app ================================================================ Fetched: 2026-07-23 15:44:05 UTC Canonical: https://phishdestroy.io/domain/bxxn.netlify.app/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 63/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 7/91 security vendors flagged this domain Flagging vendors: ESET, Emsisoft, Fortinet, LevelBlue, Netcraft, OpenPhish, Webroot Public blocklists: listed on 2 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 35.157.26.135 (DE, Frankfurt am Main) Hosting org: AS16509 Amazon.com, Inc. Registrar: Netlify Nameservers: NS_NOT_FOUND ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-23 15:22:06 UTC (by PhishDestroy tracker) Last verified: 2026-07-23 16:30:18 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f8f23-24cc-7618-85fc-7c68029a92fd/ Wayback Machine: https://web.archive.org/web/*/bxxn.netlify.app crt.sh CT logs: https://crt.sh/?q=%25.bxxn.netlify.app Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=bxxn.netlify.app AlienVault OTX: https://otx.alienvault.com/indicator/domain/bxxn.netlify.app URLhaus: https://urlhaus.abuse.ch/host/bxxn.netlify.app/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-23 15:22:37 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] bxxn.netlify.app: Confirmed Phishing Site bxxn.netlify.app was observed in multiple security feeds as a phishing infrastructure. The domain is registered through Netlify, which also provides the hosting environment; DNS resolution points to the IPv4 address 35.157.26.135, a Netlify‑owned node. VirusTotal has recorded detections from 7 out of 91 scanned security vendors, indicating that at least a minority of scanners have identified malicious behavior. The domain is listed on a single public blocklist and is actively blocked by the PhishDestroy service, confirming that defensive communities consider it hostile. Nameserver information could not be retrieved, which may reflect the use of Netlify's default DNS configuration that does not expose conventional NS records. The current operational status is reported as active, meaning the site is still reachable. No public page title, SSL certificate details, or HTTP response codes have been disclosed in the available intelligence, leaving the exact content and delivery mechanisms of the phishing page unknown. Consequently, analysts cannot verify which brand or credential collection page is being impersonated, nor can they assess the presence of obfuscated payloads or additional command‑and‑control infrastructure. Defenders should prioritize immediate containment of the address 35.157.26.135 and the host name bxxn.netlify.app in network perimeter controls, DNS filtering solutions, and endpoint security policies. Adding the domain to internal blocklists and sharing the indicator with threat‑intel platforms will reduce the chance of accidental exposure. Continuous monitoring of the domain's DNS records is advised, as changes to the underlying IP or NS configuration could indicate a shift in hosting or a takedown attempt. Correlating any future alerts that reference the same IP or Netlify infrastructure with this indicator will help to surface related campaigns. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: c43aaf35298b85d5b7acd492d32fe8b7 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/bxxn.netlify.app/ JSON API: https://api.destroy.tools/v1/check?domain=bxxn.netlify.app Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 188,904 domains (58,553 alive under monitoring, 128,729 confirmed takedowns/dead). Site: https://phishdestroy.io