# PhishDestroy threat dossier — caixageral.com ================================================================ Fetched: 2026-07-22 11:19:48 UTC Canonical: https://phishdestroy.io/domain/caixageral.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 98/100 (PhishDestroy scoring — see methodology below) Scam classification: Credential Phishing ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Webroot Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 194.145.208.36 (NL, Amsterdam) ASN: AS200514 KnownSRV Ltd. Hosting org: KnownSRV Ltd Registrar: TuringSign Inc. d/b/a Cosmotown Nameservers: ns11.knownsrv.com, ns12.knownsrv.com Registered: 2026-07-09 Expires: 2027-07-09 Page title: Caixageral Bank- Your New Favorite Bank HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-10-07 Status: INVALID chain Fingerprint: 0b844a09685fd22aef0afe7929a274f016f0f253706d4b81f56794f4459b6728 Subject Alternative Names (related infrastructure — often same operator): - caixageral.com.primetrustsasset.com - standardcapital.top - standardcapital.top.primetrustsasset.com - www.caixageral.com.primetrustsasset.com - www.standardcapital.top.primetrustsasset.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-09 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-12 17:38:09 UTC (by PhishDestroy tracker) First reported: 2026-07-12 17:37:21 UTC (abuse notice filed) Last verified: 2026-07-22 12:20:35 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f56fa-04c7-77d9-a481-923d14b1f2ea/ URLQuery: https://urlquery.net/report/3b29ad32-2f8b-4372-8867-c69518c8bb75 Wayback Machine: https://web.archive.org/web/*/caixageral.com crt.sh CT logs: https://crt.sh/?q=%25.caixageral.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=caixageral.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/caixageral.com URLhaus: https://urlhaus.abuse.ch/host/caixageral.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-12 17:47:07 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] caixageral.com Fake Login Page Alert The domain caixageral.com was registered on July 09, 2026 through the registrar TuringSign Inc., operating under the trade name Cosmotown. The registration is recent, occurring only three days before the report date of July 12, 2026. The domain is currently active and resolves to a single IPv4 address, 194.145.208.36, indicating a minimal hosting footprint. Authoritative name resolution is provided by ns11.knownsrv.com and ns12.knownsrv.com, both of which are publicly listed nameservers. No additional A or AAAA records were observed, and reverse DNS for the hosting IP does not resolve to a recognizable corporate network. The limited DNS surface suggests the operator is using a straightforward, low‑complexity deployment typical of opportunistic phishing infrastructure. Threat intelligence categorizes caixageral.com as a generic phishing site, although the specific brand or service being spoofed has not been identified in the available data. The absence of any malicious detections on VirusTotal (0/95) does not imply benign intent; the site may be in an early stage of deployment before samples reach public scanners. Uncertainty remains regarding the content hosted at the URL, the credential‑harvesting mechanisms employed, and any potential command‑and‑control links. Defenders should treat the domain as hostile until further evidence clarifies its purpose. Recommended mitigation steps include adding the domain and its resolving IP address to block lists at perimeter firewalls and DNS filtering solutions, monitoring outbound traffic for connections to 194.145.208.36, and employing sink‑hole techniques if feasible. Continuous re‑analysis of the domain through automated sandboxing and periodic VirusTotal rescans is advised to detect any evolution in malicious payloads. [Updates since narrative was generated:] - VirusTotal detections: now 2/91 (narrative was written when count was lower) ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260712-CDFCF1 Favicon MD5: d144111517fdd9dd9dd33edd51a46fc6 TLS cert SHA-256: 0b844a09685fd22aef0afe7929a274f016f0f253706d4b81f56794f4459b6728 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/caixageral.com/ JSON API: https://api.destroy.tools/v1/check?domain=caixageral.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 188,008 domains (57,476 alive under monitoring, 128,899 confirmed takedowns/dead). Site: https://phishdestroy.io