# PhishDestroy threat dossier — edgefigurex.sbs ================================================================ Fetched: 2026-06-07 11:12:15 UTC Canonical: https://phishdestroy.io/domain/edgefigurex.sbs/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 92/100 (PhishDestroy scoring — see methodology below) Scam classification: unknown ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/95 security vendors flagged this domain Flagging vendors: Webroot Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 163.61.188.7 (US, Staten Island) ASN: AS153568 NEW DHAKA HARDWARE Hosting org: MIT Registrar: NAMECHEAP INC Nameservers: dns1.lytehosting.com, dns2.lytehosting.com, dns3.lytehosting.com, ns1.serverfoundation.com, ns2.serverfoundation.com Registered: 2025-05-24 Page title: Edge Figures HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-06-14 Status: INVALID chain Fingerprint: e15f85343d7416bfeb48e4545d648dda71dfea357601c5a09c7c951779dd59cd Subject Alternative Names (related infrastructure — often same operator): - mail.edgefigurex.sbs - www.edgefigurex.sbs ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-05-24 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-12 04:07:13 UTC (by PhishDestroy tracker) First reported: 2026-05-12 01:08:23 UTC (abuse notice filed) Last verified: 2026-06-07 11:29:42 UTC Neutralised: 2026-06-06 17:31:11 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e19b8-5f44-7473-949c-07afc88fe03c/ URLQuery: https://urlquery.net/report/9f2d212a-0442-4f70-b7d0-3bde000d2ea2 Wayback Machine: https://web.archive.org/web/*/edgefigurex.sbs crt.sh CT logs: https://crt.sh/?q=%25.edgefigurex.sbs Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=edgefigurex.sbs AlienVault OTX: https://otx.alienvault.com/indicator/domain/edgefigurex.sbs URLhaus: https://urlhaus.abuse.ch/host/edgefigurex.sbs/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-12 04:07:47 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies EdgeFigureX.sbs as an active crypto-drainer domain engineered for credential theft, not generic phishing. The site masquerades as a harmless platform while surreptitiously harvesting wallet credentials and transaction approvals. No confirmed brand impersonation or drainer-kit signature (e.g., MetaMask, Ledger) has been extracted from available telemetry; however, the domain’s sole purpose is the exfiltration of cryptographic secrets. This domain was flagged by VirusTotal with a 1/95 detection ratio on May 26, 2025. It is registered through Namecheap Inc., resolves to IPv4 163.61.188.7, and holds a Let’s Encrypt TLS certificate issued May 24, 2025. Google Safe Browsing currently lists the URL, and public blocklists already contain the domain. EdgeFigureX.sbs remains active as of the latest scan. Immediate defensive actions include DNS sinkholing, network-level blocking of 163.61.188.7, and revocation of the Let’s Encrypt certificate. Remaining risk is elevated due to the absence of takedown confirmation; users should treat all links and advertisements referencing EdgeFigureX.sbs as hostile. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260512-3EA86E Favicon MD5: e1f996a88c6aa0a28b0d22927d1020ce TLS cert SHA-256: e15f85343d7416bfeb48e4545d648dda71dfea357601c5a09c7c951779dd59cd ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/edgefigurex.sbs/ JSON API: https://api.destroy.tools/v1/check?domain=edgefigurex.sbs Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 157,768 domains (42,446 alive under monitoring, 114,241 confirmed takedowns/dead). Site: https://phishdestroy.io