# PhishDestroy threat dossier — crypttex-eid.com ================================================================ Fetched: 2026-07-21 01:32:28 UTC Canonical: https://phishdestroy.io/domain/crypttex-eid.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 88/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain Public blocklists: listed on 2 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 144.124.233.86 (NL, Amsterdam) ASN: AS216071 SERVERS TECH FZCO Hosting org: Servers Tech Fzco Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com Nameservers: ns1.vdsina.com, ns2.vdsina.com, ns3.vdsina.com, ns4.vdsina.com Registered: 2026-07-10 Expires: 2027-07-10 Page title: Crypttex HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-10-09 Status: INVALID chain Fingerprint: b583d7654ca85585c868e937090a7b748109f919af915338dc31f7efd0cc7c72 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-10 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-19 07:16:35 UTC (by PhishDestroy tracker) First reported: 2026-07-19 05:18:28 UTC (abuse notice filed) Last verified: 2026-07-21 00:24:44 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f78cd-42ca-727a-90f6-a82e8cc5aa1d/ URLQuery: https://urlquery.net/report/9d56456a-be9f-46b6-979a-03ff69725579 Wayback Machine: https://web.archive.org/web/*/crypttex-eid.com crt.sh CT logs: https://crt.sh/?q=%25.crypttex-eid.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=crypttex-eid.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/crypttex-eid.com URLhaus: https://urlhaus.abuse.ch/host/crypttex-eid.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-19 07:16:45 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is crypttex-eid.com a phishing site? crypttex-eid.com was registered through PDR Ltd. d/b/a PublicDomainRegistry.com on 10 July 2026. The domain resolves to IP 144.124.233.86 and remains active as of 19 July 2026. Automated analysis on VirusTotal shows the domain has been scanned by 95 security vendors, with no current detections; the lack of alerts does not constitute evidence of safety. The intelligence source classifies the site as a generic phishing infrastructure, and the risk level is listed as under_investigation. No public content, page title, or associated brand information has been disclosed, so the exact phishing lure employed cannot be confirmed. The short lifespan and recent creation suggest a purpose‑built campaign, and the use of a public‑domain registrar is a common tactic to obtain quick, cheap registration. Defenders should consider adding the domain and its resolved IP address to block lists, monitor DNS queries for anomalous resolution patterns, and enforce outbound traffic controls to prevent credential exfiltration. Continuous re‑scanning on multi‑vendor platforms is advised to capture any future malicious payloads that may be associated with the domain. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260719-82B61C Favicon MD5: fa0a74885da06344637053273e3fd133 TLS cert SHA-256: b583d7654ca85585c868e937090a7b748109f919af915338dc31f7efd0cc7c72 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/crypttex-eid.com/ JSON API: https://api.destroy.tools/v1/check?domain=crypttex-eid.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 187,409 domains (57,206 alive under monitoring, 128,551 confirmed takedowns/dead). Site: https://phishdestroy.io