# PhishDestroy threat dossier — chainsalyses.com ================================================================ Fetched: 2026-06-30 06:20:01 UTC Canonical: https://phishdestroy.io/domain/chainsalyses.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Credential Phishing ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 8/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, CyRadar, Ermes, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Kaspersky URLQuery: 2 detections Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 158.94.209.240 (NL, Amsterdam) ASN: ASAS202412 OMEGATECH-AS Omegatech LTD, SC Hosting org: AS202412 Omegatech LTD Registrar: UnstoppableUS2 LLC Nameservers: ns1.unstoppabledomains.com, ns2.unstoppabledomains.com Registered: 2026-06-22 Expires: 2027-06-22 Page title: The Blockchain Data Platform - Chainalysis HTTP response: 526 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE1 Expires: 2026-09-20 Status: INVALID chain Fingerprint: 902f0cb3f2ef69d52be66cf391071523dbcdd83df2503571d5ee5cb54416c45c Subject Alternative Names (related infrastructure — often same operator): - www.chainsalyses.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-06-22 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-06-26 14:19:36 UTC (by PhishDestroy tracker) First reported: 2026-06-26 12:23:25 UTC (abuse notice filed) Last verified: 2026-06-30 06:17:14 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f03de-01f1-7698-9a7b-6f6a04ec7c20/ URLQuery: https://urlquery.net/report/63b336e6-0281-4859-864f-670ca5b41944 Wayback Machine: https://web.archive.org/web/*/chainsalyses.com crt.sh CT logs: https://crt.sh/?q=%25.chainsalyses.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=chainsalyses.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/chainsalyses.com URLhaus: https://urlhaus.abuse.ch/host/chainsalyses.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-26 14:37:13 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] This domain, chainsalyses.com, poses a high-risk credential harvesting threat targeting users of legitimate blockchain analysis platforms. The site mimics the branding and page structure of an established blockchain data provider, presenting a login interface to deceive visitors into submitting sensitive account credentials. Such phishing campaigns are commonly used to gain unauthorized access to financial accounts, cryptocurrency wallets, or enterprise systems associated with blockchain monitoring tools. Analysis indicates this domain was registered on June 22, 2026, through the registrar UnstoppableUS2 LLC, an entity frequently observed in recent phishing infrastructure deployments. The domain resolves to the IP address 158.94.209.240, which has been linked to multiple transient phishing hosts in prior campaigns. As of the latest scan, 3 out of 95 security detection engines on a widely used malware analysis platform have flagged chainsalyses.com as malicious, with signatures indicating generic phishing behavior. The site employs a Let's Encrypt SSL certificate, a common tactic to lend false legitimacy to fraudulent pages. Users who have visited chainsalyses.com or entered credentials on the site should immediately revoke any submitted login details from all associated accounts. It is recommended to reset passwords using a secure, unrelated device and enable multi-factor authentication where available. System administrators should block the domain and IP address 158.94.209.240 at the network perimeter. Affected individuals should monitor accounts for unauthorized transactions and report any suspicious activity to their financial or security providers. No legitimate service will request sensitive information through unsolicited or mimicked login portals. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260626-EAF81C Favicon MD5: a0b5fe83c90de4528f38fc12f4b3818d TLS cert SHA-256: 902f0cb3f2ef69d52be66cf391071523dbcdd83df2503571d5ee5cb54416c45c ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/chainsalyses.com/ JSON API: https://api.destroy.tools/v1/check?domain=chainsalyses.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 172,677 domains (13,093 alive under monitoring, 158,994 confirmed takedowns/dead). Site: https://phishdestroy.io