# PhishDestroy threat dossier — criptoprimes.com ================================================================ Fetched: 2026-07-24 23:38:30 UTC Canonical: https://phishdestroy.io/domain/criptoprimes.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Credential Phishing ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 6/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, Netcraft, SOCRadar URLQuery: 2 detections Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 198.251.83.50 (US, Staten Island) ASN: AS53667 FranTech Solutions Hosting org: FranTech Solutions Registrar: Atak Domain Nameservers: ns103.my-control-panel.com, ns104.my-control-panel.com Registered: 2026-06-11 Expires: 2027-06-09 Page title: CriptoPrimes HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE1 Expires: 2026-09-08 Status: INVALID chain Fingerprint: a6807620b81d73d8689d67376306b8b9a9f45a948131da0c73c75943cb121506 Subject Alternative Names (related infrastructure — often same operator): - ftp.criptoprimes.com - mail.criptoprimes.com - pop.criptoprimes.com - smtp.criptoprimes.com - www.criptoprimes.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-06-11 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-06-11 22:23:35 UTC (by PhishDestroy tracker) Earliest abuse rec: 2026-06-11 20:26:29 UTC — PREDATES current WHOIS registration; retained from a previous registration cycle of the same domain name Last verified: 2026-07-25 00:20:36 UTC Current status: ACTIVE / observable Note: one or more events above predate the WHOIS creation date. This typically means the same domain name was previously registered, detected, dropped, and then re-registered by a new party. PhishDestroy preserves the full historical record for operator-attribution research even when the underlying infrastructure changes hands. ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019eb858-ea0e-7392-a549-9644b164162e/ URLQuery: https://urlquery.net/report/6a83b7e8-dbdb-4f9d-9dd4-e5953e652b61 Wayback Machine: https://web.archive.org/web/*/criptoprimes.com crt.sh CT logs: https://crt.sh/?q=%25.criptoprimes.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=criptoprimes.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/criptoprimes.com URLhaus: https://urlhaus.abuse.ch/host/criptoprimes.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-13 00:21:19 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] criptoprimes.com: Confirmed Credential Phishing Site Targeting Analysis of the domain criptoprimes.com indicates active credential phishing infrastructure targeting cryptocurrency users. Registered on June 11, 2026, through the registrar Atak Domain, the domain resolves to IP address 198.251.83.50, hosted by FranTech Solutions in the United States. Nameservers ns103.my-control-panel.com and ns104.my-control-panel.com are associated with the domain, which currently returns an HTTP 200 status, signaling an operational web server. The domain is flagged by three security blocklists, including PhishDestroy, MetaMask, and SEAL, and holds a Gridinsoft trust score of 0/100. Six of 91 security vendors on VirusTotal detect the domain as malicious. The page title 'CriptoPrimes' and the classified scam type 'Credential Phishing' suggest an intent to harvest login credentials, likely under the guise of a cryptocurrency-related service. Technologies detected on the domain include LiteSpeed, Smartsupp, jQuery, GetButton, and HTTP/3, which are consistent with modern phishing sites designed to appear legitimate. The SSL certificate is issued by Let's Encrypt (YE1), a common choice for both legitimate and malicious sites due to its free and automated issuance process. Defenders should treat this domain as high-risk and block it at the network level. The use of bulletproof hosting providers and the domain's recent registration further support the assessment of ongoing malicious activity. No legitimate use case has been identified, and the domain remains active as of July 12, 2026. Additional monitoring of associated infrastructure, such as the hosting IP and nameservers, is recommended to identify related threats. [Updates since narrative was generated:] - VirusTotal detections: now 6/91 (narrative was written when count was lower) ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260611-F1CE4E Favicon MD5: 6bce06f171739d06c548b9ba339d427d TLS cert SHA-256: a6807620b81d73d8689d67376306b8b9a9f45a948131da0c73c75943cb121506 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/criptoprimes.com/ JSON API: https://api.destroy.tools/v1/check?domain=criptoprimes.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 189,348 domains (58,436 alive under monitoring, 129,348 confirmed takedowns/dead). Site: https://phishdestroy.io