# PhishDestroy threat dossier — cv34f3d.christmas ================================================================ Fetched: 2026-07-29 14:08:25 UTC Canonical: https://phishdestroy.io/domain/cv34f3d.christmas/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: generic ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 47.242.217.10 (HK, Hong Kong) ASN: AS45102 Alibaba (US) Technology Co., Ltd. Hosting org: Hong Kong Registrar: Spaceship, Inc. Nameservers: launch1.spaceship.net, launch2.spaceship.net Registered: 2026-07-18 Expires: 2027-07-18 Page title: cv34f3d.christmas HTTP response: 200 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-18 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-28 02:30:30 UTC (by PhishDestroy tracker) First reported: 2026-07-28 00:37:18 UTC (abuse notice filed) Last verified: 2026-07-29 15:02:25 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa61f-80f0-77eb-ad9f-9e89604ce001/ URLQuery: https://urlquery.net/report/58e32bb7-8086-4b24-8bf9-96ed509eca65 Wayback Machine: https://web.archive.org/web/*/cv34f3d.christmas crt.sh CT logs: https://crt.sh/?q=%25.cv34f3d.christmas Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=cv34f3d.christmas AlienVault OTX: https://otx.alienvault.com/indicator/domain/cv34f3d.christmas URLhaus: https://urlhaus.abuse.ch/host/cv34f3d.christmas/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 02:31:37 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] cv34f3d.christmas Phishing Campaign Detected On July 28, 2026, analysis of the domain cv34f3d.christmas identified an active generic phishing infrastructure. The domain was registered on July 18, 2026 through Spaceship, Inc., using the authoritative name servers launch1.spaceship.net and launch2.spaceship.net. DNS resolution points to the IPv4 address 47.242.217.10, which remains reachable as of the report date. The domain is listed on one public security blocklist and has been blocked by the PhishDestroy sinkhole, indicating that at least one defensive platform has observed malicious traffic associated with the host. VirusTotal records show that the domain was scanned by 91 antivirus and URL‑analysis engines, none of which have raised a detection at the time of scanning. While the lack of detections does not imply benign intent, it confirms that the domain has not yet triggered automated signatures in the examined vendor set. No additional intelligence such as Safe Browsing verdicts, Open Threat Exchange references, SSL certificate details, HTTP response codes, or trust‑score metrics were available for this host. Given the recent creation date, the presence on a blocklist, and active resolution to a public IP, the infrastructure is likely being used to host phishing pages or to relay malicious traffic. Defenders should add cv34f3d.christmas to URL filtering rules, monitor DNS queries for the two launch*.spaceship.net name servers, and consider network‑level blocking of the associated IP address. Continuous re‑scanning with multi‑engine services is recommended to capture any future changes in detection status. Incident response teams should treat any communications originating from this domain as suspicious and verify user credentials through out‑of‑band channels before proceeding. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260728-6D0446 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/cv34f3d.christmas/ JSON API: https://api.destroy.tools/v1/check?domain=cv34f3d.christmas Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,478 domains (83,245 alive under monitoring, 109,716 confirmed takedowns/dead). Site: https://phishdestroy.io