# PhishDestroy threat dossier — caseid-1605plkqzm.integradatalink.com ================================================================ Fetched: 2026-05-21 01:47:34 UTC Canonical: https://phishdestroy.io/domain/caseid-1605plkqzm.integradatalink.com/ ## VERDICT ---------------------------------------------------------------- ACTIVE THREAT — multiple warning signs Composite threat score: 50/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 14/95 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, ESET, Fortinet, G-Data, Google Safebrowsing, Kaspersky, Lionic, OpenPhish, Sophos, VIPRE, Webroot ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.96.3 Registrar: GMO Internet, Inc. Nameservers: jim.ns.cloudflare.com, luciane.ns.cloudflare.com Registered: 2026-04-07 Page title: Business Help Center HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E8 Expires: 2026-07-06 Status: INVALID chain Fingerprint: 33d7575aeb936954e8d12b402e17a4a5c9c9c3edf678b9fde38ee64bd90e7ecc Subject Alternative Names (related infrastructure — often same operator): - integradatalink.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-07 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-21 03:11:43 UTC (by PhishDestroy tracker) Last verified: 2026-05-21 04:42:59 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e47de-df87-77ac-8224-af4880cccd3f/ Wayback Machine: https://web.archive.org/web/*/caseid-1605plkqzm.integradatalink.com crt.sh CT logs: https://crt.sh/?q=%25.caseid-1605plkqzm.integradatalink.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=caseid-1605plkqzm.integradatalink.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/caseid-1605plkqzm.integradatalink.com URLhaus: https://urlhaus.abuse.ch/host/caseid-1605plkqzm.integradatalink.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-21 03:12:42 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies caseid-1605plkqzm.integradatalink.com as an active crypto drainer domain impersonating a secure login portal. The threat level is classified as elevated due to its use of transparent social engineering tactics to trick users into connecting crypto wallets or submitting credentials. This domain primarily targets cryptocurrency users by mimicking legitimate authentication interfaces, particularly in DeFi and Web3 ecosystems. The risk is elevated because it has already been detected by multiple security vendors and remains accessible, suggesting ongoing operations. This domain was flagged by 13 out of 95 VirusTotal security vendors, indicating significant but not universal detection. It resolves to IP address 188.114.96.3 and uses a Let's Encrypt SSL certificate, suggesting attempts to appear legitimate. Registered through GMO Internet, Inc., the domain was created on April 07, 2026, indicating it is very new and potentially still in active deployment. The combination of low age, high IP association risk, and partial detection coverage elevates the threat profile. As a crypto drainer, this domain likely employs malicious JavaScript to drain wallet funds upon connection or harvest seed phrases. Immediate mitigation steps are required. Users should avoid interacting with this domain entirely — do not click links, open attachments, or input any credentials. Block the domain at the network level using DNS or firewall rules (e.g., block caseid-1605plkqzm.integradatalink.com and 188.114.96.3). Scan all connected wallets for unauthorized approvals or transactions, and revoke any suspicious smart contract permissions via tools like Etherscan or WalletConnect. Report this domain to PhishDestroy and local threat intelligence platforms for blocking and takedown escalation. If compromised, move funds immediately to a new wallet with a different seed phrase and enable hardware wallet security. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: 33d7575aeb936954e8d12b402e17a4a5c9c9c3edf678b9fde38ee64bd90e7ecc ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/caseid-1605plkqzm.integradatalink.com/ JSON API: https://api.destroy.tools/v1/check?domain=caseid-1605plkqzm.integradatalink.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 152,190 domains (42,927 alive under monitoring, 108,981 confirmed takedowns/dead). Site: https://phishdestroy.io