# PhishDestroy threat dossier — cookiedao.vip ================================================================ Fetched: 2026-04-30 17:40:31 UTC Canonical: https://phishdestroy.io/domain/cookiedao.vip/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 13/95 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, Bfore.Ai PreCrime, BitDefender, CRDF, CyRadar, ESET, Fortinet, G-Data, Google Safebrowsing, Lionic, Sophos, VIPRE URLQuery: 2 detections Public blocklists: listed on 1 independent blocklist Google Safe Browsing: FLAGGED ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.97.3 Registrar: Dynadot Inc Nameservers: ligia.ns.cloudflare.com, milan.ns.cloudflare.com Registered: 2025-09-28 Page title: COOKIE DAO REWARDS | COOKIE DAO Official Staking | COOKIE DAO BSC HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-06-22 Status: INVALID chain Fingerprint: e32ef25798fb3fcef44e15b8a27ebc8affacda58d4c0983285bc64e04b4372cf ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-09-28 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-30 17:38:36 UTC (by PhishDestroy tracker) First reported: 2026-04-30 14:39:47 UTC (abuse notice filed) Last verified: 2026-04-30 19:50:06 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019dded2-92c9-7460-a88b-00b8c573b559/ URLQuery: https://urlquery.net/report/5c97d0f4-e0c3-4f2a-a6b2-5f19c6aa306e Wayback Machine: https://web.archive.org/web/*/cookiedao.vip crt.sh CT logs: https://crt.sh/?q=%25.cookiedao.vip Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=cookiedao.vip AlienVault OTX: https://otx.alienvault.com/indicator/domain/cookiedao.vip URLhaus: https://urlhaus.abuse.ch/host/cookiedao.vip/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-30 17:39:47 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies cookiedao.vip as an active cryptocurrency-themed phishing domain distributing fake wallet or token offers to steal digital assets and credentials. This site masquerades as a legitimate decentralized finance initiative under the name CookieDAO, but all indicators confirm malicious intent designed to harvest private keys, seed phrases or browser-stored passwords from unsuspecting users. The threat is classified as high-risk due to its rapid deployment timeline and confirmed detection across multiple security platforms, indicating active and ongoing use in fraudulent campaigns. This domain was flagged by 13 out of 95 antivirus engines on VirusTotal, placed on one public blocklist, and blocked by InversionDNS. It was registered through Dynadot Inc on September 28, 2025, and resolves to IP 188.114.97.3 with an SSL certificate issued by Google Trust Services. Google Safe Browsing classifies the site under “SOCIAL_ENGINEERING,” confirming its use in deceptive practices aimed at tricking users into revealing sensitive financial or identity information. The combination of recent registration, compromised reputation, and certificate issuance suggests a coordinated phishing operation likely leveraging social media or messaging platforms to spread links under the guise of a new crypto project. If you visited cookiedao.vip or entered any credentials, immediately disconnect from the internet, revoke any exposed API keys or wallets, and perform a malware scan using a reputable security tool. Never reuse passwords across services and consider rotating all crypto wallet credentials stored in browser extensions or local files. Report the domain to your security team and monitor financial accounts for unauthorized transactions. For a complete threat analysis and indicator feed, visit the full report to obtain IOCs (Indicators of Compromise) and mitigation steps tailored to your environment. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260430-980597 Favicon MD5: 4480e2c541222d4f12f2836ba419a423 TLS cert SHA-256: e32ef25798fb3fcef44e15b8a27ebc8affacda58d4c0983285bc64e04b4372cf ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/cookiedao.vip/ JSON API: https://api.destroy.tools/v1/check?domain=cookiedao.vip Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io