# PhishDestroy threat dossier — changenow-app.org ================================================================ Fetched: 2026-07-27 06:31:32 UTC Canonical: https://phishdestroy.io/domain/changenow-app.org/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 93/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 16/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Kaspersky, LevelBlue, Lionic, Sophos, VIPRE URLQuery: 2 detections AlienVault OTX: 4 pulses (threat-intel feed mentions) Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 130.12.180.128 (NL, Amsterdam) ASN: AS202412 Omegatech LTD Hosting org: Virtualine Technologies Registrar: Dynadot Inc Nameservers: ns1.dyna-ns.net, ns2.dyna-ns.net Registered: 2026-05-19 Expires: 2027-05-19 Page title: ChangeNOW | Crypto Exchange ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE1 Expires: 2026-10-16 Status: INVALID chain Fingerprint: afa822fa8f51b558c09f35c42b32e556daa9968e5e7a0b4474cca235851f482f Subject Alternative Names (related infrastructure — often same operator): - www.changenow-app.org ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-19 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 05:49:13 UTC (by PhishDestroy tracker) First reported: 2026-07-27 04:58:36 UTC (abuse notice filed) Last verified: 2026-07-27 08:31:21 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa1af-05ef-706e-9eba-1e26666074e8/ URLQuery: https://urlquery.net/report/45abcda4-b115-46cd-82ed-221627e4381f Wayback Machine: https://web.archive.org/web/*/changenow-app.org crt.sh CT logs: https://crt.sh/?q=%25.changenow-app.org Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=changenow-app.org AlienVault OTX: https://otx.alienvault.com/indicator/domain/changenow-app.org URLhaus: https://urlhaus.abuse.ch/host/changenow-app.org/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 05:50:53 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] changenow-app.org used for high‑risk generic phishing Analysis indicates that the domain changenow-app.org was registered on May 19 2026 through Dynadot Inc. The authoritative nameservers ns1.dyna-ns.net and ns2.dyna-ns.net resolve the domain to the IPv4 address 130.12.180.128. As of the report date, the domain remains active and is listed on three public security blocklists. VirusTotal scans show that 16 out of 91 antivirus and URL‑reputation engines flag the domain as malicious, confirming a consensus of suspicion among a substantial minority of vendors. Independent blocklist providers PhishDestroy, MetaMask and SEAL have also added the domain to their deny lists, indicating that the site is being used to deliver phishing payloads that target users of cryptocurrency wallets and related services. The available intelligence does not include a publicly observed SSL certificate, HTTP response codes, page title, or any observed malicious payloads, so the exact delivery mechanism and the specific content served remain unknown. Likewise, no attribution to a particular phishing kit or campaign has been disclosed, and the geographic location of the hosting provider has not been published. The lack of these details limits the ability to attribute the activity beyond the observed infrastructure. Defenders should block DNS resolution for changenow-app.org at the network perimeter and ensure that endpoint protection solutions incorporate the domain into their URL filtering policies. Email gateways should treat any messages containing links to this domain as malicious, and security teams should monitor outbound traffic for connections to the IP address 130.12.180.128. Because the domain is newly created, rapid detection of any new subdomains or related hostnames is advisable. Continuous re‑evaluation of the domain’s reputation on VirusTotal and other aggregators is recommended, as additional detections may emerge. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-D51CEE Favicon MD5: 8ac03768d1cf65ba50c9d6f4503620a8 TLS cert SHA-256: afa822fa8f51b558c09f35c42b32e556daa9968e5e7a0b4474cca235851f482f ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/changenow-app.org/ JSON API: https://api.destroy.tools/v1/check?domain=changenow-app.org Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 203,167 domains (78,589 alive under monitoring, 123,547 confirmed takedowns/dead). Site: https://phishdestroy.io