# PhishDestroy threat dossier — conscientiousyouth.org ================================================================ Fetched: 2026-07-24 10:17:56 UTC Canonical: https://phishdestroy.io/domain/conscientiousyouth.org/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Brand Impersonation ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 5/91 security vendors flagged this domain Flagging vendors: Fortinet Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 163.61.188.7 (US, Staten Island) ASN: AS153568 NEW DHAKA HARDWARE Hosting org: MIT Registrar: TuringSign Inc. d/b/a Cosmotown Nameservers: dns1.lytehosting.com, dns2.lytehosting.com, dns3.lytehosting.com, dns4.lytehosting.com, ns1.serverfoundation.com, ns2.serverfoundation.com Registered: 2025-11-20 Expires: 2026-11-20 Page title: CYEF - Conscientious Youth Empowerment Foundation HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R13 Expires: 2026-08-25 Status: INVALID chain Fingerprint: af992e3dce92197ab4653b4dd18dfa24607786b9d40e83bb5f3950085174121b Subject Alternative Names (related infrastructure — often same operator): - conscientiousyouth.org.prmc.agency - www.conscientiousyouth.org.prmc.agency ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-11-20 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-01 03:59:07 UTC (by PhishDestroy tracker) First reported: 2026-07-01 02:16:49 UTC (abuse notice filed) Last verified: 2026-07-24 12:10:39 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f1b65-553a-727c-a310-6e45f44be323/ URLQuery: https://urlquery.net/report/3f3b3398-afe0-421d-a4e5-82e0a6cd7941 Wayback Machine: https://web.archive.org/web/*/conscientiousyouth.org crt.sh CT logs: https://crt.sh/?q=%25.conscientiousyouth.org Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=conscientiousyouth.org AlienVault OTX: https://otx.alienvault.com/indicator/domain/conscientiousyouth.org URLhaus: https://urlhaus.abuse.ch/host/conscientiousyouth.org/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-01 04:46:11 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] conscientiousyouth.org CYEF Foundation Impersonator Analysis indicates that conscientiousyouth.org delivers a targeted impersonation of the Conscientious Youth Empowerment Foundation to harvest credentials and personal data from visitors seeking youth programs. The site presents the exact page title CYEF - Conscientious Youth Empowerment Foundation while operating from infrastructure configured for credential theft rather than legitimate nonprofit activity. Infrastructure analysis reveals a VirusTotal score of 1/95 security vendors, registration through TuringSign Inc. d/b/a Cosmotown on November 20 2025, presence on exactly 1 security blocklist, an active Let's Encrypt certificate, and resolution to IP address 163.61.188.7. Gridinsoft trust score registers at 0/100 with the domain remaining active and continuing to serve content that matches known phishing patterns. Users who accessed conscientiousyouth.org should immediately reset all passwords entered on the page, enable multi-factor authentication on associated accounts, review financial and email records for unauthorized access, and clear browser cache and cookies. Any devices used to visit the domain require full antivirus scans followed by verification that no unauthorized software or browser extensions were installed during the session. [Updates since narrative was generated:] - VirusTotal detections: now 5/91 (narrative was written when count was lower) ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260701-AEDDDE Favicon MD5: decfd22a5641572895c4a9db1d4d0f0f TLS cert SHA-256: af992e3dce92197ab4653b4dd18dfa24607786b9d40e83bb5f3950085174121b ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/conscientiousyouth.org/ JSON API: https://api.destroy.tools/v1/check?domain=conscientiousyouth.org Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 189,173 domains (58,549 alive under monitoring, 129,006 confirmed takedowns/dead). Site: https://phishdestroy.io