# PhishDestroy threat dossier — dappresolves.com ================================================================ Fetched: 2026-08-01 19:50:49 UTC Canonical: https://phishdestroy.io/domain/dappresolves.com/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 84/100 (PhishDestroy scoring — see methodology below) Scam classification: Wallet/Seed Phishing Targeted brand: foundation (and: ledger, sui, trezor) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/95 security vendors flagged this domain Flagging vendors: Gridinsoft, Seclookup Public blocklists: listed on 4 independent blocklists Victim re-reports (public form): 1 ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 102.212.246.90 (US, Dallas) ASN: ASAS329278 truehostcloud, KE Hosting org: AS329278 Truehost Cloud Limited Registrar: OwnRegistrar, Inc. Nameservers: 1 Registered: 2025-09-11 Expires: 2025-09-22 Page title: DappSResolve ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: none Status: INVALID chain ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-09-11 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-02-25 02:39:27 UTC (by PhishDestroy tracker) First reported: 2025-09-15 06:29:23 UTC (abuse notice filed) Last verified: 2026-08-01 20:21:51 UTC Neutralised: 2026-05-11 19:47:31 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/01994cb5-0596-734f-b9d1-c2a8a32ac8aa/ Wayback Machine: https://web.archive.org/web/*/dappresolves.com crt.sh CT logs: https://crt.sh/?q=%25.dappresolves.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=dappresolves.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/dappresolves.com URLhaus: https://urlhaus.abuse.ch/host/dappresolves.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-24 16:38:57 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] dappresolves.com: Seed Phishing Impersonating foundation The domain dappresolves.com was registered on September 11, 2025 through OwnRegistrar, Inc. and is presently hosted on a single IP address (102.212.246.90) belonging to Truehost Cloud Limited (AS329278) in the United States. The site presents the page title "DappSResolve" and does not serve an SSL/TLS certificate, indicating that all traffic is transmitted over plain HTTP. Infrastructure analysis shows a Gridinsoft trust score of 0 out of 100, reflecting an extremely low reputation for the host. The domain resolves to one nameserver, and its registration details are publicly visible, suggesting no use of privacy protection services. Detection services have flagged the domain: two of ninety‑five VirusTotal scanners reported it as malicious, and four independent blocklists—PhishDestroy, Polkadot, Enkrypt, and Codeesura—have listed the domain as a known threat. The reported scam type is wallet/seed phishing, and the domain is explicitly noted to impersonate the brand "foundation". No additional evidence such as Safe Browsing or Open Threat Exchange entries is available in the current intelligence set. The combination of a brand‑impersonation claim, lack of encryption, a zero‑trust score, and multiple blocklist entries indicates a high confidence that dappresolves.com is being used for credential harvesting targeting users of the foundation ecosystem. However, the limited number of VirusTotal detections and the absence of publicly disclosed payload samples leave some uncertainty about the exact phishing flow and whether any additional malicious components are hosted on the same IP. Defenders should immediately add the domain and its IP address to deny‑list rules across network perimeter devices, DNS filters, and endpoint protection platforms. Because the site is currently offline, monitoring for any re‑appearance or a shift to alternative hosting infrastructure is advised. ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/dappresolves.com/ JSON API: https://api.destroy.tools/v1/check?domain=dappresolves.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 177,802 domains (72,628 alive under monitoring, 27,318 confirmed neutralized). Site: https://phishdestroy.io