# PhishDestroy threat dossier — en-ndx-x-portal.square.site ================================================================ Fetched: 2026-07-22 19:20:37 UTC Canonical: https://phishdestroy.io/domain/en-ndx-x-portal.square.site/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Fake Exchange ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 8/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, ESET, Emsisoft, Fortinet, Kaspersky, LevelBlue, Netcraft, Webroot Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 74.115.51.5 (US, Oakland) ASN: ASAS27647 WEEBLY - Weebly, Inc., US Hosting org: AS27647 Weebly, Inc. Registrar: Square, Inc. Nameservers: NS_NOT_FOUND Page title: Ndax - Login | Canada's most secure crypto exchange HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE2 Expires: 2026-10-03 Status: INVALID chain Fingerprint: 2409b45b254819793d9c558542323d21d5340f0e444a50a275a3462d6fbe7ef0 Subject Alternative Names (related infrastructure — often same operator): - square.site ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-21 02:16:25 UTC (by PhishDestroy tracker) Last verified: 2026-07-22 20:20:23 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f8206-cdc4-76eb-a01c-2518c555b9cc/ Wayback Machine: https://web.archive.org/web/*/en-ndx-x-portal.square.site crt.sh CT logs: https://crt.sh/?q=%25.en-ndx-x-portal.square.site Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=en-ndx-x-portal.square.site AlienVault OTX: https://otx.alienvault.com/indicator/domain/en-ndx-x-portal.square.site URLhaus: https://urlhaus.abuse.ch/host/en-ndx-x-portal.square.site/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-21 02:17:32 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] en-ndx-x-portal.square.site used for high‑risk phishing Analysis on en-ndx-x-portal.square.site indicates that the domain is actively used for phishing operations as of the report date 21 July 2026. The domain resolves to the IPv4 address 74.115.51.5 and is listed as active in the intelligence feed. Registration information shows the domain was provisioned through Square, Inc., but the authoritative name server records could not be resolved (NS_NOT_FOUND), which hampers further DNS‑based attribution. Malware scanning on VirusTotal returned a detection ratio of 8 / 95 security vendors, confirming that a subset of commercial scanners have identified malicious behavior associated with the host. The domain is currently blocked by the PhishDestroy mitigation service and appears on one external security blocklist, reinforcing its classification as high‑risk. No additional public artifacts such as Safe Browsing verdicts, Open Threat Exchange entries, SSL certificate details, HTTP response codes, or page titles have been observed, leaving those vectors unverified. The limited visibility of the hosting environment and lack of name‑server data introduce uncertainty regarding the full infrastructure scope and potential affiliate domains. Defenders should immediately add en‑ndx‑x‑portal.square.site and the associated IP address 74.115.51.5 to network‑level deny lists, configure URL filtering to block any HTTP/HTTPS requests to the domain, and monitor DNS logs for any resolution attempts. Continuous re‑query of VirusTotal and threat‑intel platforms is recommended to capture any changes in detection scores or new blocklist entries. Organizations employing email security gateways should enforce strict URL reputation checks and quarantine messages that contain redirects to this domain. Periodic passive DNS and WHOIS monitoring may reveal future name‑server updates or registration changes that could indicate further malicious activity. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 77566019b83ef54c6d2a0eb1fc7059c1 TLS cert SHA-256: 2409b45b254819793d9c558542323d21d5340f0e444a50a275a3462d6fbe7ef0 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/en-ndx-x-portal.square.site/ JSON API: https://api.destroy.tools/v1/check?domain=en-ndx-x-portal.square.site Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 188,340 domains (57,785 alive under monitoring, 128,922 confirmed takedowns/dead). Site: https://phishdestroy.io