# PhishDestroy threat dossier — dovevip.cc ================================================================ Fetched: 2026-07-23 14:49:57 UTC Canonical: https://phishdestroy.io/domain/dovevip.cc/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 13/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Lionic, Sophos, VIPRE, Webroot Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.97.3 (US, San Francisco) ASN: ASAS13335 CLOUDFLARENET - Cloudflare, Inc., US Hosting org: AS13335 Cloudflare, Inc. Registrar: NameSilo, LLC !!! REGISTRAR INTEGRITY ALERT — NameSilo !!! NameSilo is a registrar documented by PhishDestroy as (1) publicly lying about received abuse reports, (2) shielding a $20M+ Monero-theft operation (xmrwallet.com) for 10 continuous years, and (3) retaliating against PhishDestroy by getting our X/Twitter account @Phish_Destroy banned after we published the evidence. Researchers/victims must ALWAYS CC compliance@icann.org on every abuse ticket — NameSilo has a track record of later claiming reports were never received. Primary sources: https://phishdestroy.io/namesilo-killed-our-twitter https://phishdestroy.io/xmrwallet-namesilo-exposed Nameservers: kolton.ns.cloudflare.com, violet.ns.cloudflare.com Registered: 2025-12-25 Expires: 2026-12-25 Page title: 用户中心 - DOVE加速器 | 唯一官方网站 | 安全加密和高速稳定的全球网络服务商 - DOVE加速器官网 HTTP response: 302 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-09-18 Status: INVALID chain Fingerprint: 2c5e37addb9fbf1097626b2b745636eb423ea3e4256f52b323f2e68eaf914517 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-12-25 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-23 05:24:02 UTC (by PhishDestroy tracker) Last verified: 2026-07-23 16:20:24 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f8cff-87bd-766f-add9-696ac1c7a9c4/ Wayback Machine: https://web.archive.org/web/*/dovevip.cc crt.sh CT logs: https://crt.sh/?q=%25.dovevip.cc Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=dovevip.cc AlienVault OTX: https://otx.alienvault.com/indicator/domain/dovevip.cc URLhaus: https://urlhaus.abuse.ch/host/dovevip.cc/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-23 05:24:21 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] dovevip.cc Used in High-Risk Phishing Threat – Active Warning The domain dovevip.cc is currently assessed as a high-risk generic phishing threat based on multiple technical indicators. Registered through NameSilo, LLC on December 25, 2025, the domain remains active as of July 23, 2026. DNS records show that it resolves to IP address 188.114.97.3 and utilizes Cloudflare nameservers (kolton.ns.cloudflare.com and violet.ns.cloudflare.com), which can be indicative of attempts to obscure hosting details or leverage protection features common among phishing infrastructure operators. Detection data from VirusTotal reveals that 13 out of 95 security vendors have flagged dovevip.cc for malicious or phishing-related activity. This detection rate, while not universal, demonstrates significant consensus among threat intelligence vendors regarding the domain’s risk profile. Additionally, dovevip.cc has been actively blocked by the PhishDestroy security blocklist, further confirming its association with phishing operations. The domain’s presence on at least one major blocklist and its ongoing resolution to a live IP indicate that it remains a potential threat to users and organizations. No additional context is available regarding the specific content or targeted brands associated with this domain, as there is no evidence from page titles or other on-page data. The lack of such detail means the exact nature of the phishing scheme hosted at dovevip.cc is not yet analyzed. Defenders should treat all traffic to this domain as high risk, implement immediate blocking at network and endpoint layers, and monitor for any related indicators of compromise. Further investigation is recommended if evidence of user interaction with this domain is detected. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: d48231d04e03aece4e108340b566539c TLS cert SHA-256: 2c5e37addb9fbf1097626b2b745636eb423ea3e4256f52b323f2e68eaf914517 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/dovevip.cc/ JSON API: https://api.destroy.tools/v1/check?domain=dovevip.cc Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 188,898 domains (58,547 alive under monitoring, 128,729 confirmed takedowns/dead). Site: https://phishdestroy.io