# PhishDestroy threat dossier — defidatchain.com ================================================================ Fetched: 2026-04-21 20:04:39 UTC Canonical: https://phishdestroy.io/domain/defidatchain.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 97/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 11/94 security vendors flagged this domain ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 104.21.82.16 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: Name SRS AB Nameservers: kianchau.ns.cloudflare.com, sue.ns.cloudflare.com Registered: 2026-04-04 Page title: DeFi Trading HTTP response: 530 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E7 Expires: 2026-07-04 Status: INVALID chain Fingerprint: 0dd173f57f17ef8db698718672ba1c3d6c1f7a321efd641f285348603a5eb360 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-04 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-15 16:44:57 UTC (by PhishDestroy tracker) First reported: 2026-04-15 13:48:20 UTC (abuse notice filed) Last verified: 2026-04-21 23:03:54 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019d9161-5bd3-7194-b7fd-6aafcac205b4/ URLQuery: https://urlquery.net/report/20b769d7-2c2b-4920-b42f-ab9d7e08a748 Wayback Machine: https://web.archive.org/web/*/defidatchain.com crt.sh CT logs: https://crt.sh/?q=%25.defidatchain.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=defidatchain.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/defidatchain.com URLhaus: https://urlhaus.abuse.ch/host/defidatchain.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-15 16:47:11 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies defidatchain.com as an active cryptocurrency draining scam posing under the guise of a DeFi trading platform. The domain is engineered to deceive users into connecting their wallets and approving malicious token approvals, resulting in unauthorized fund transfers. With the threat type classified as a crypto drainer, the risk level remains under formal investigation due to low detection coverage and recent operational activity. This domain should be treated as HIGH RISK until further evidence proves otherwise. This domain was flagged by PhishDestroy on April 04, 2026, the same date it was registered through Name SRS AB. It currently resolves to IP 104.21.82.16 and is secured with a Let's Encrypt SSL certificate. VirusTotal shows 0 detections out of 95 security engines as of the latest scan. It remains unlisted on major blocklists including Google Safe Browsing, PhishTank, and OpenPhish. The page title displayed is 'DeFi Trading,' which mimics legitimate decentralized finance platforms. Despite its new registration and low detection rate, the domain is actively hosting a fraudulent trading interface designed to exploit user trust in DeFi ecosystems. To mitigate exposure to this crypto drainer, users should avoid visiting or interacting with defidatchain.com. Never connect cryptocurrency wallets or approve token permissions on unfamiliar platforms. Use hardware wallets for sensitive transactions and verify URLs through official project websites. Report the domain to your security provider and crypto wallet if funds are at risk. Monitor wallet approvals via blockchain explorers and revoke suspicious permissions immediately using tools like revoke.cash. Exercise heightened caution with newly registered domains offering high-yield trading or 'too good to be true' incentives. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260415-73C449 TLS cert SHA-256: 0dd173f57f17ef8db698718672ba1c3d6c1f7a321efd641f285348603a5eb360 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/defidatchain.com/ JSON API: https://api.destroy.tools/v1/check?domain=defidatchain.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io