# PhishDestroy threat dossier — chekad.cc ================================================================ Fetched: 2026-06-20 17:03:57 UTC Canonical: https://phishdestroy.io/domain/chekad.cc/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users (type: referer_split) (score: 1/6) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 18/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, CRDF, CyRadar, Emsisoft, Forcepoint ThreatSeeker, Fortinet, Gridinsoft, Kaspersky, Netcraft, SOCRadar URLQuery: 2 detections AlienVault OTX: 1 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 168.76.218.206 (HK, Tung Chung) Hosting org: AS137951 ASLINE LIMITED Registrar: Gname.com Pte. Ltd. Nameservers: a.share-dns.com, a2.share-dns.com, b.share-dns.net, b2.share-dns.net Registered: 2026-04-15 Expires: 2027-04-15 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-07-14 Status: INVALID chain Fingerprint: 657ac2447a4691d09a8bbc99b073be19471f726005310146fb22b2c8a21a7bc8 Subject Alternative Names (related infrastructure — often same operator): - www.chekad.cc ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-15 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-06-14 14:37:19 UTC (by PhishDestroy tracker) First reported: 2026-06-17 14:55:07 UTC (abuse notice filed) Last verified: 2026-06-20 16:20:35 UTC Neutralised: 2026-06-17 00:18:33 UTC Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019ecad9-a343-7171-8649-5e6d8349019c/ URLQuery: https://urlquery.net/report/ac7bf4c1-73ee-40dc-8557-a9be0aba0f9d Wayback Machine: https://web.archive.org/web/*/chekad.cc crt.sh CT logs: https://crt.sh/?q=%25.chekad.cc Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=chekad.cc AlienVault OTX: https://otx.alienvault.com/indicator/domain/chekad.cc URLhaus: https://urlhaus.abuse.ch/host/chekad.cc/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-18 16:37:59 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Chekad.cc is a dangerous phishing site specifically designed as a crypto drainer, meaning it attempts to trick visitors into connecting their cryptocurrency wallets or entering private keys, which then allows attackers to steal funds. This site masquerades as a legitimate service to harvest sensitive information and drain digital assets. This is not a generic phishing attempt but a targeted threat aimed at cryptocurrency users. PhishDestroy's analysis confirms this threat with alarming precision. VirusTotal data shows that 18 out of 95 security vendors flag this domain as malicious, a strong indicator of widespread detection. The domain was created on April 15, 2026, which is unusually recent and a red flag for fraudulent activity. It was registered through Gname.com Pte. Ltd., a registrar often associated with questionable domains. The SSL certificate is issued by Let's Encrypt R12, which is commonly abused by phishers. Additionally, the domain appears in one AlienVault OTX threat intelligence pulse and on one security blocklist, confirming its malicious nature. The site is currently offline, but that does not guarantee safety for those who already visited. If you have visited chekad.cc, take immediate action. Do not enter any passwords, recovery phrases, or private keys. If you connected a cryptocurrency wallet, transfer all assets to a new, secure wallet immediately and revoke any permissions granted to the site. Run a full security scan on your device using reputable antivirus software. Monitor your accounts for unauthorized activity and consider enabling two-factor authentication everywhere. Stay vigilant and avoid interacting with unsolicited links or sites with suspicious domain names and recent creation dates. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260617-95451E Favicon MD5: 146d3781c1050eed48bc35cc7cd8aa52 TLS cert SHA-256: 657ac2447a4691d09a8bbc99b073be19471f726005310146fb22b2c8a21a7bc8 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/chekad.cc/ JSON API: https://api.destroy.tools/v1/check?domain=chekad.cc Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 166,768 domains (13,080 alive under monitoring, 153,370 confirmed takedowns/dead). Site: https://phishdestroy.io