# PhishDestroy threat dossier — couponfollow.sale ================================================================ Fetched: 2026-07-27 04:56:25 UTC Canonical: https://phishdestroy.io/domain/couponfollow.sale/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 83/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 104.21.51.160 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED !!! REGISTRAR INTEGRITY ALERT — NiceNIC !!! NiceNIC International: over 90% of its registered domains are associated with illegal content; documented systematic abuse-report non-response. Primary sources: https://phishdestroy.io/nicenic-real https://phishdestroy.io/nicenic-verdict Nameservers: keanu.ns.cloudflare.com, ullis.ns.cloudflare.com Registered: 2026-07-21 Expires: 2027-07-21 Page title: The Free App Quietly Saving Shoppers Hundreds at Checkout | The Consumer Chronicle HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-10-19 Status: INVALID chain Fingerprint: f9b7de294657e996db554b07ae0b5e5312614c49e9a18220daae7899f491f3e9 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-21 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-26 15:19:15 UTC (by PhishDestroy tracker) Last verified: 2026-07-27 04:20:56 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f9e93-9eec-712c-a0e6-80a6979fcb0a/ Wayback Machine: https://web.archive.org/web/*/couponfollow.sale crt.sh CT logs: https://crt.sh/?q=%25.couponfollow.sale Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=couponfollow.sale AlienVault OTX: https://otx.alienvault.com/indicator/domain/couponfollow.sale URLhaus: https://urlhaus.abuse.ch/host/couponfollow.sale/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-26 15:21:22 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] couponfollow.sale Phishing Site Detected Analysis of couponfollow.sale was performed on 2026-07-26 following its appearance on a public blocklist. The domain is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED and was created on 2026-07-21, indicating a very recent deployment. DNS resolution points to IP address 104.21.51.160, which is hosted behind Cloudflare as evidenced by the authoritative nameservers keanu.ns.cloudflare.com and ullis.ns.cloudflare.com. The domain is classified as a generic phishing threat based on the supplied intelligence, and it currently appears on one security blocklist, specifically PhishDestroy, which has taken active measures to block the host. VirusTotal reports that the domain has been scanned by 91 antivirus and URL‑reputation vendors, yet none of the vendors have raised a detection at the time of scanning. While the lack of detections does not constitute a safety assurance, it demonstrates that the malicious infrastructure has not yet been fingerprinted by the participating scanners. No additional public reputation sources such as Google Safe Browsing, OTX, or SSL certificate transparency logs are available for this domain at the time of review. Consequently, the observable surface consists of registration details, hosting information, and blocklist status. Uncertainty remains regarding the actual payload delivered, the phishing kit employed, and any compromised credentials that may be exfiltrated. Defenders should add couponfollow.sale to internal URL filtering policies, monitor DNS queries for the domain and its associated IP, and consider proactive blocking at the firewall or proxy level. Continuous re‑evaluation is advised, as future scans by additional vendors or updates to blocklists may reveal further malicious activity. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: f9b7de294657e996db554b07ae0b5e5312614c49e9a18220daae7899f491f3e9 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/couponfollow.sale/ JSON API: https://api.destroy.tools/v1/check?domain=couponfollow.sale Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 202,551 domains (77,973 alive under monitoring, 123,547 confirmed takedowns/dead). Site: https://phishdestroy.io