Evidence Facts
PhishDestroy first observed cleanandgreen.us on Jun 15, 2026. Stored page analysis classifies the content as credential phishing. Evidence score: 100/100 (critical).
3 independent sources recorded positive findings: VirusTotal, MetaMask, and SEAL. VirusTotal recorded 12 detections among 91 engines: alphaMountain.ai, Sophos on Jul 18, 2026 at 16:04 UTC. MetaMask and SEAL listed the hostname in the separate external-blocklist snapshot on Aug 9, 2026 at 10:20 UTC.
Cloaking was recorded with HTTP 200 on Aug 9, 2026 at 02:49 UTC. The cloaking probe recorded status split conditional delivery at 1/100 on Aug 9, 2026 at 02:49 UTC: alive_content: raw=ok; http=200; via=https_proxy. The recorded creation date for the domain is May 27, 2026. At collection time, the hostname resolved to 13.248.169.48 on AS16509 (Amazon.com, Inc.).
Data coverage12 recorded checks
Threat Response Pipeline
Public Blocklist Status
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
VirusTotal Analysis
Evidence & External ReportsIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.