# PhishDestroy threat dossier — chatcams18.com ================================================================ Fetched: 2026-07-22 20:12:26 UTC Canonical: https://phishdestroy.io/domain/chatcams18.com/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 73/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 64.31.3.237 (US, Salt Lake City) ASN: AS46475 Limestone Networks, Inc. Hosting org: Limestone Networks Registrar: Dynadot Inc Nameservers: ["ns1.brainydns.com", "ns2.brainydns.com"] Page title: Chatcams18 HTTP response: 302 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-09-06 Status: INVALID chain Fingerprint: 87c2bf829ac45fe48fc50712d1b480c7311a189521a0c54a6e7b33d593345212 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-19 13:29:37 UTC (by PhishDestroy tracker) Last verified: 2026-07-22 20:20:23 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-19 13:37:00 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] chatcams18.com — Adult-Themed Phishing Site Investigation This domain, chatcams18.com, is under active investigation for phishing activity targeting adult entertainment users. As of July 19, 2026, the domain remains operational despite being flagged on one security blocklist and blocked by PhishDestroy. Infrastructure analysis reveals an HTTP 302 redirect status, which is commonly used to obscure final landing pages or evade detection. While 91 security vendors scanned the domain on VirusTotal, none currently flag it as malicious; however, the absence of detections does not confirm safety, as phishing domains often evade initial scans through rapid infrastructure changes or obfuscation techniques. The exact content and brand impersonation tactics of the site are not yet analyzed, but the domain name suggests a focus on adult webcam services, a frequent target for credential theft or fraudulent subscription schemes. Defenders should treat this domain as high-risk until further evidence is gathered, particularly given its persistence despite blocklist inclusion. Network-level blocking is recommended, and security teams should monitor for connections to this domain in logs, as it may indicate compromised credentials or attempted fraud. Further analysis is required to determine the full scope of the threat, including the final destination of the 302 redirect and any associated malicious infrastructure. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: 87c2bf829ac45fe48fc50712d1b480c7311a189521a0c54a6e7b33d593345212 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/chatcams18.com/ JSON API: https://api.destroy.tools/v1/check?domain=chatcams18.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 188,412 domains (57,857 alive under monitoring, 128,922 confirmed takedowns/dead). Site: https://phishdestroy.io