# PhishDestroy threat dossier — claims-blackbullsol.app ================================================================ Fetched: 2026-07-25 22:35:38 UTC Canonical: https://phishdestroy.io/domain/claims-blackbullsol.app/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Crypto Drainer ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/91 security vendors flagged this domain Flagging vendors: Forcepoint ThreatSeeker, Fortinet Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 62.60.226.88 (DE, Frankfurt am Main) ASN: ASAS214351 FEMOIT FEMO IT SOLUTIONS LIMITED, GB Hosting org: AS214351 FEMO IT SOLUTIONS LIMITED Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED !!! REGISTRAR INTEGRITY ALERT — NiceNIC !!! NiceNIC International: over 90% of its registered domains are associated with illegal content; documented systematic abuse-report non-response. Primary sources: https://phishdestroy.io/nicenic-real https://phishdestroy.io/nicenic-verdict Nameservers: coco.bunny.net, kiki.bunny.net Registered: 2026-07-24 Expires: 2027-07-24 Page title: The Black Bull | $ANSEM HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-10-22 Status: INVALID chain Fingerprint: fc595deeb13556fc7185038bd17c73782174297cb9c4aaeeb0f5a462c55d4752 Subject Alternative Names (related infrastructure — often same operator): - www.claims-blackbullsol.app ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-24 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-25 07:41:58 UTC (by PhishDestroy tracker) First reported: 2026-07-25 05:49:59 UTC (abuse notice filed) Last verified: 2026-07-26 00:28:10 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f97d5-795a-7579-ad0b-3c140b2bab8a/ URLQuery: https://urlquery.net/report/01e7a081-0a6b-4ce0-904c-246724e32673 Wayback Machine: https://web.archive.org/web/*/claims-blackbullsol.app crt.sh CT logs: https://crt.sh/?q=%25.claims-blackbullsol.app Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=claims-blackbullsol.app AlienVault OTX: https://otx.alienvault.com/indicator/domain/claims-blackbullsol.app URLhaus: https://urlhaus.abuse.ch/host/claims-blackbullsol.app/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-25 07:43:18 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] claims-blackbullsol.app Safety Check — Crypto Drainer Analysis of claims-blackbullsol.app shows that the domain was registered on 24 July 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and is currently active. The authoritative name servers are coco.bunny.net and kiki.bunny.net, and the domain resolves to the IPv4 address 62.60.226.88. Reputation services have flagged the domain as a crypto drainer: two of ninety‑one VirusTotal scanners reported malicious activity, and the domain is listed on a single public security blocklist. PhishDestroy has also added the domain to its blocklist, indicating that it is being actively mitigated by at least one anti‑phishing service. No additional intelligence such as SSL certificate details, HTTP response codes, or page title has been disclosed, so the exact payload or delivery mechanism remains unknown. The limited detection footprint suggests a recent deployment, consistent with the creation date of the domain only one day prior to the report. Defenders should treat the domain as high‑risk: network perimeter controls should block DNS resolution to 62.60.226.88, firewall rules should deny outbound connections to the host, and endpoint security policies should include the domain in URL filtering lists. Continuous monitoring of the IP reputation and periodic rescans with VirusTotal or similar platforms are recommended to capture any evolution in the malicious profile. Organizations that handle cryptocurrency transactions should be especially vigilant for attempts to redirect users to this domain, as the threat classification indicates attempts to exfiltrate crypto assets. [Updates since narrative was generated:] - WHOIS creation date: 2026-07-24 ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260725-A5459C Favicon MD5: 224d90934c32d9c3b39b8b66ae2675f8 TLS cert SHA-256: fc595deeb13556fc7185038bd17c73782174297cb9c4aaeeb0f5a462c55d4752 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/claims-blackbullsol.app/ JSON API: https://api.destroy.tools/v1/check?domain=claims-blackbullsol.app Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 193,449 domains (63,100 alive under monitoring, 128,796 confirmed takedowns/dead). Site: https://phishdestroy.io