canna272i7uai6h5ctkrrfttwv2naulak37gctk22t6erohxegtu45yd[.]top
Forensic brief
PhishDestroy identifies the domain canna272i7uai6h5ctkrrfttwv2naulak37gctk22t6erohxegtu45yd.top as a generic phishing page impersonating CannaExpress with a fake 'Access Queue' login portal. This domain employs a crypto drainer kit designed to harvest wallet credentials and initiate unauthorized transactions upon authentication. The page mimics a legitimate cannabis e-commerce queue system, tricking users into entering sensitive wallet information under the guise of order processing. This domain resolves to IP 172.67.143.85 and was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on February 04, 2026. VirusTotal currently reports 0 out of 95 detections, indicating it remains undetected by most antivirus engines. The domain holds a valid SSL certificate issued by Google Trust Services, which may further deceive users into believing the site is legitimate. As of this report, it has not been flagged by major blocklists such as Google Safe Browsing. The domain remains active and poses an ongoing risk due to its low detection profile and deceptive branding. PhishDestroy has flagged this as a high-priority threat requiring immediate user awareness and verification. Users are advised to avoid interacting with this domain and to report any suspicious activity. Remaining risk includes the potential for additional phishing pages or drainer variants to emerge under similar naming conventions. Immediate action includes domain takedown requests and updating browser blocklists to prevent further exploitation.
Threat response pipeline
Cloudflare Radar
VirusTotal
Forensic Evidence Collectionabuse@nicenic.net,abuse@nic.top with forensic evidence (metadata, screenshots, PDF).Evidence capture
Domain Intelligence
NICENIC INTERNATIONAL GROUP CO., LIMITED
Technical details
Forensic dossier — wire captures
canna272i7uai6h5ctkrrfttwv2naulak37gctk22t6erohxegtu45yd.top → 172.67.143.85
EVIDENCEGET / HTTP/1.1 Host: canna272i7uai6h5ctkrrfttwv2naulak37gctk22t6erohxegtu45yd.top (via shadow IP: 172.67.143.85) HTTP/1.1 200 OK content-length: 59351<title>CannaExpress Access Queue</title> # CDN-fronted, but origin is directly reachable bypassing Cloudflare.
Public blocklist status
Technologies
Technologies · 3 identified
VirusTotal consensus
Aggregated detection across 95 security vendors.
Site performance
Site performance analysis
Google PageSpeed Insights — mobile audit of canna272i7uai6h5ctkrrfttwv2naulak37gctk22t6erohxegtu45yd.top
Evidence & external reports
Were you affected by this site?
Were You Affected?
Report to your local authorities
Email template — registrar abuse
abuse@nicenic.net
Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED Case: PD-PD-20260510-452C03
Embed this report
About this report
About this report: canna272i7uai6h5ctkrrfttwv2naulak37gctk22t6erohxegtu45yd.top
This domain security report is maintained by PhishDestroy's automated threat-intelligence pipeline. Our system continuously monitors this domain across 95 security vendors on VirusTotal and 1 public blocklists.
The site displays a page titled “CannaExpress Access Queue”.
canna272i7uai6h5ctkrrfttwv2naulak37gctk22t6erohxegtu45yd.top has been flagged by 2 security vendors as of May 17, 2026.
If you believe this listing is inaccurate, you can submit an appeal. For more information about our methodology, visit our FAQ page.