# PhishDestroy threat dossier — byboilusdt.com ================================================================ Fetched: 2026-06-27 21:18:07 UTC Canonical: https://phishdestroy.io/domain/byboilusdt.com/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: cryptocurrency Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users (type: status_split) (score: 1/6) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 14/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Kaspersky, Lionic, PhishFort, SOCRadar, Sophos AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 156.254.5.115 (MY, Kuala Lumpur) ASN: ASAS154376 CLOUDVALLEY-AS-AP - Cloudvalley Sdn. Bhd., MY Hosting org: AS154376 Cloudvalley Sdn. Bhd. Registrar: Gname.com Pte. Ltd. Nameservers: a.share-dns.com, a7.share-dns.com, b.share-dns.net, b7.share-dns.net Registered: 2026-06-08 Expires: 2027-06-08 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-09-06 Status: INVALID chain Fingerprint: 561a0d254b79b0f088dd51fa5fb7298b74af3fb2f14894c28bb25421280ef4cd Subject Alternative Names (related infrastructure — often same operator): - binuvusdt.com - bybnxcusdt.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-06-08 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-06-10 23:26:46 UTC (by PhishDestroy tracker) First reported: 2026-06-10 21:28:44 UTC (abuse notice filed) Last verified: 2026-06-27 20:20:35 UTC Neutralised: 2026-06-14 00:46:00 UTC Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019eb36d-73af-72ce-8cc2-1459919492da/ URLQuery: https://urlquery.net/report/a71eadd5-35ee-4bc5-a917-1ddbcf087548 Wayback Machine: https://web.archive.org/web/*/byboilusdt.com crt.sh CT logs: https://crt.sh/?q=%25.byboilusdt.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=byboilusdt.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/byboilusdt.com URLhaus: https://urlhaus.abuse.ch/host/byboilusdt.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-26 00:05:40 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] This domain, byboilusdt.com, is flagged as an elevated-risk cryptocurrency phishing threat. Analysis indicates it operates under the generic_phishing classification, specifically targeting users of digital asset platforms through deceptive interfaces designed to harvest credentials or misappropriate funds. The risk level is substantiated by multiple technical indicators and threat intelligence sources. Infrastructure analysis reveals the domain was registered on June 8, 2026, through Gname.com Pte. Ltd., a registrar frequently associated with high-risk domains. It resolves to the IP address 156.254.5.115 and employs a Let's Encrypt SSL certificate, a common tactic to lend superficial legitimacy. Detection metrics further underscore its malicious nature: VirusTotal reports 14 out of 95 security vendors flagging the domain, while AlienVault OTX lists it in two distinct threat intelligence pulses. The domain appears on one security blocklist and is actively blocked by at least one anti-phishing system. Additionally, Gridinsoft assigns it a trust score of 0/100, reflecting unanimous consensus on its fraudulent intent. Mitigation against cryptocurrency phishing threats requires a multi-layered approach. Users should verify domain registration details via WHOIS lookups, cross-referencing creation dates and registrars against known legitimate platforms. Suspicious domains resolving to IPs with poor reputational histories—such as 156.254.5.115—should be treated as high-risk. Enabling multi-factor authentication on all digital asset accounts and employing browser-based security extensions that block known phishing domains can reduce exposure. Organizations should integrate threat intelligence feeds into network security controls to preemptively block domains flagged by multiple vendors, such as those detected by 14/95 security engines in this case. Immediate reporting of such domains to relevant threat-sharing platforms can aid in broader disruption efforts. [Updates since narrative was generated:] - VirusTotal detections: now 14/91 (narrative was written when count was lower) ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260610-8D4D1C TLS cert SHA-256: 561a0d254b79b0f088dd51fa5fb7298b74af3fb2f14894c28bb25421280ef4cd ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/byboilusdt.com/ JSON API: https://api.destroy.tools/v1/check?domain=byboilusdt.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 170,938 domains (12,748 alive under monitoring, 157,778 confirmed takedowns/dead). Site: https://phishdestroy.io