# PhishDestroy threat dossier — deficentrixprime.com ================================================================ Fetched: 2026-07-30 03:05:04 UTC Canonical: https://phishdestroy.io/domain/deficentrixprime.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Crypto Drainer ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 6/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, Netcraft, SOCRadar AlienVault OTX: 1 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 66.70.148.18 (CA, Beauharnois) ASN: AS16276 OVH SAS Hosting org: Dedicated Serve Registrar: TuringSign Inc. d/b/a Cosmotown Nameservers: ns5.ddoscure.com, ns6.ddoscure.com, protected3.ddoscure.com, protected4.ddoscure.com Registered: 2025-12-20 Expires: 2026-12-20 Page title: Deficentrixprime | Home HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-09-19 Status: INVALID chain Fingerprint: d71ffd24263806297421a00fd67e4992ee85ddee20a4b3102c810a418f07eb94 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-12-20 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 05:47:08 UTC (by PhishDestroy tracker) First reported: 2026-07-27 05:19:00 UTC (abuse notice filed) Last verified: 2026-07-30 04:20:24 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa1b7-29fb-735b-8a34-897acae87d4e/ URLQuery: https://urlquery.net/report/efc96df1-087d-45d1-865c-f141afa82d9f Wayback Machine: https://web.archive.org/web/*/deficentrixprime.com crt.sh CT logs: https://crt.sh/?q=%25.deficentrixprime.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=deficentrixprime.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/deficentrixprime.com URLhaus: https://urlhaus.abuse.ch/host/deficentrixprime.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 05:50:53 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] deficentrixprime.com Crypto Drainer Scam – Active Threat Alert Analysis indicates the domain deficentrixprime.com is an active crypto drainer threat, currently under investigation as of July 27, 2026. Registered on December 20, 2025, through TuringSign Inc. d/b/a Cosmotown, the domain employs nameservers ns5.ddoscure.com, ns6.ddoscure.com, protected3.ddoscure.com, and protected4.ddoscure.co, suggesting a pattern of infrastructure reuse within the ddoscure nameserver cluster. The domain resolves to the IP address 66.70.148.18, though no autonomous system number or geolocation data is currently associated with this address in the available intelligence. No detections were recorded by the 91 vendors that scanned the domain on VirusTotal, though the absence of flags does not confirm benign status. The domain appears on one security blocklist and is actively blocked by PhishDestroy, indicating prior identification as malicious by at least one threat intelligence provider. The unique seed identifier dee809 has been assigned for tracking purposes. Infrastructure analysis reveals the domain remains operational, with no reported takedown or suspension by the registrar. The specific content hosted on deficentrixprime.com has not been fully analysed, and no page title, brand target, or phishing kit details are available in the current dataset. Defenders are advised to treat this domain as high-risk for cryptocurrency theft, particularly given its classification as a crypto drainer. Network-level blocking of the domain and its resolving IP (66.70.148.18) is recommended pending further analysis. Additional monitoring of the ddoscure nameserver infrastructure may reveal related threats, as this appears to be a shared hosting pattern among similar campaigns. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-AC401B Favicon MD5: 6e0ac5e55413574e23a3f395f3c993cb TLS cert SHA-256: d71ffd24263806297421a00fd67e4992ee85ddee20a4b3102c810a418f07eb94 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/deficentrixprime.com/ JSON API: https://api.destroy.tools/v1/check?domain=deficentrixprime.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,547 domains (93,372 alive under monitoring, 99,913 confirmed takedowns/dead). Site: https://phishdestroy.io