# PhishDestroy threat dossier — coinshores.net ================================================================ Fetched: 2026-07-27 05:56:27 UTC Canonical: https://phishdestroy.io/domain/coinshores.net/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 12/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar, ESET, Fortinet, G-Data, Gridinsoft, Lionic, Sophos, VIPRE AlienVault OTX: 1 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 5.182.209.88 Registrar: NAMECHEAP INC Nameservers: ns1.pwxs.net, ns2.pwxs.net Registered: 2022-12-24 Expires: 2026-12-24 Page title: CoinShores - #1 Investment Platform for Traders and Investors ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-10-08 Status: INVALID chain Fingerprint: f7b79b855caf353d9cc23ca3189aaa01507e7c7055828fcd1d2d1d74a322e766 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2022-12-24 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 05:50:22 UTC (by PhishDestroy tracker) First reported: 2026-07-27 05:04:51 UTC (abuse notice filed) Last verified: 2026-07-27 07:15:17 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa1af-e764-7676-880b-b9a0ae0517f6/ URLQuery: https://urlquery.net/report/58ef3d34-6cdd-4d3d-a8de-9fc9154b6742 Wayback Machine: https://web.archive.org/web/*/coinshores.net crt.sh CT logs: https://crt.sh/?q=%25.coinshores.net Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=coinshores.net AlienVault OTX: https://otx.alienvault.com/indicator/domain/coinshores.net URLhaus: https://urlhaus.abuse.ch/host/coinshores.net/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 05:53:23 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] coinshores.net Safety Check — Phishing Campaign Detected Analysis of coinshores.net as of July 27, 2026 shows that the domain was registered on December 24, 2022 through Namecheap Inc. The authoritative name servers are ns1.pwxs.net and ns2.pwxs.net, and DNS resolution points to the IPv4 address 5.182.209.88. The domain is currently classified as a generic phishing site and remains active. Reputation data indicates that the domain is listed on a single security blocklist and has been blocked by the PhishDestroy service. VirusTotal reports twelve detections out of ninety‑one scanning engines, confirming that multiple security products consider the host malicious. No additional public signals such as Safe Browsing entries, Open Threat Exchange tags, SSL certificate details, or HTTP status codes are available in the current intelligence set. Consequently, the precise content and target brand of the phishing page have not been disclosed. Defenders should treat coinshores.net as hostile infrastructure. Immediate actions include adding the domain and its resolving IP address to network deny lists, updating intrusion‑prevention signatures, and ensuring that email filtering rules reference the domain as a malicious indicator. Continuous monitoring of the associated name servers and any future VirusTotal or blocklist submissions is advised to capture changes in the threat posture. Organizations that employ threat‑intelligence feeds should ingest the reported detection count and blocklist presence to improve detection coverage. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-EE151E Favicon MD5: 209c91d04087035104d8d32a32511c2f TLS cert SHA-256: f7b79b855caf353d9cc23ca3189aaa01507e7c7055828fcd1d2d1d74a322e766 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/coinshores.net/ JSON API: https://api.destroy.tools/v1/check?domain=coinshores.net Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 202,968 domains (78,390 alive under monitoring, 123,547 confirmed takedowns/dead). Site: https://phishdestroy.io