# PhishDestroy threat dossier — dogecoinqianbaoxiazai.cam ================================================================ Fetched: 2026-07-31 19:34:40 UTC Canonical: https://phishdestroy.io/domain/dogecoinqianbaoxiazai.cam/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 5/91 security vendors flagged this domain Flagging vendors: ChainPatrol, alphaMountain.ai, CRDF, Gridinsoft, SOCRadar URLQuery: 3 detections Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 154.216.118.199 (SC, Tung Chung) ASN: ASAS132839 POWERLINE-AS-AP - POWER LINE DATACENTER, HK Hosting org: AS132839 POWER LINE DATACENTER Registrar: Dynadot Inc Nameservers: molly.ns.cloudflare.com, roman.ns.cloudflare.com Registered: 2026-05-26 Expires: 2027-05-26 Page title: 狗狗币钱包下载 - 官方安全Dogecoin钱包 | 支持Windows/Mac/Linux HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-10-25 Status: INVALID chain Fingerprint: abbc6fcc7990944f18c0fcba94a6bd79466e778facd4bd020d564256975556e9 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-26 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-29 02:55:07 UTC (by PhishDestroy tracker) First reported: 2026-07-29 01:00:28 UTC (abuse notice filed) Last verified: 2026-07-31 20:20:24 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fab5d-5bf0-722d-a2b6-03a5be9f8ee5/ URLQuery: https://urlquery.net/report/16cd7040-35ca-4f10-9e53-3b359539508f Wayback Machine: https://web.archive.org/web/*/dogecoinqianbaoxiazai.cam crt.sh CT logs: https://crt.sh/?q=%25.dogecoinqianbaoxiazai.cam Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=dogecoinqianbaoxiazai.cam AlienVault OTX: https://otx.alienvault.com/indicator/domain/dogecoinqianbaoxiazai.cam URLhaus: https://urlhaus.abuse.ch/host/dogecoinqianbaoxiazai.cam/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-29 02:55:35 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] dogecoinqianbaoxiazai.cam Safety Check — Phishing Detected by On July 29, 2026, the domain dogecoinqianbaoxiazai.cam was identified as active and under investigation for phishing-related activity. The domain was registered through Dynadot Inc and created on May 26, 2026. Infrastructure analysis shows that it currently resolves to IP address 154.216.118.199 and uses Cloudflare-managed nameservers (molly.ns.cloudflare.com and roman.ns.cloudflare.com), which is common for domains seeking to utilize proxy and mitigation services. The domain has been included on one security blocklist, specifically flagged by PhishDestroy, indicating at least one trusted intelligence source currently evaluates this domain as associated with phishing operations. However, wider industry detection is not yet observed; a VirusTotal scan by 91 vendors did not result in any positive identifications at the time of analysis. This absence of further detections should not be interpreted as evidence of safety, especially while the domain remains listed by a reputable anti-phishing blocklist. Other public threat intelligence platforms such as OTX or Safe Browsing have not been mentioned in the available data, and the precise content or tactics associated with the domain have not been analyzed as of this report. The risk level is listed as under investigation, and as such, defenders are advised to treat the domain as suspicious and monitor for any related activity on their networks. Communication or interaction with the domain should be avoided until further evidence is available. Security teams should consider implementing blocks or alerts based on the domain name and associated IP and remain attentive to additional intelligence updates. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260729-B3CF58 TLS cert SHA-256: abbc6fcc7990944f18c0fcba94a6bd79466e778facd4bd020d564256975556e9 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/dogecoinqianbaoxiazai.cam/ JSON API: https://api.destroy.tools/v1/check?domain=dogecoinqianbaoxiazai.cam Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 196,669 domains (84,388 alive under monitoring, 27,268 confirmed neutralized). Site: https://phishdestroy.io