# PhishDestroy threat dossier — fixedfl-oat.org ================================================================ Fetched: 2026-06-07 18:18:25 UTC Canonical: https://phishdestroy.io/domain/fixedfl-oat.org/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Fake Exchange ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Gridinsoft URLQuery: 2 detections Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 176.125.242.151 (MD, Chisinau) ASN: AS200019 ALEXHOST SRL Hosting org: Alexhost SRL Registrar: Dynadot Inc Nameservers: ["ns1.dyna-ns.net", "ns2.dyna-ns.net"] Registered: 2026-04-26 Page title: FixedFloat | Exchange & Swap ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R13 Expires: 2026-06-24 Status: INVALID chain Fingerprint: d9c0ed0cb81a05d2f8d3a30cb37c32982c95b6e4c2ca59db29179852d2f168ce Subject Alternative Names (related infrastructure — often same operator): - www.fixedfl-oat.org ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-26 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-26 17:06:57 UTC (by PhishDestroy tracker) First reported: 2026-04-26 14:10:41 UTC (abuse notice filed) Last verified: 2026-06-07 16:07:29 UTC Neutralised: 2026-06-06 17:34:43 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019dca1b-f985-721d-8d9c-a8225b0a0b8e/ URLQuery: https://urlquery.net/report/06dc4886-5954-4af0-be69-99b7fdcd34d4 Wayback Machine: https://web.archive.org/web/*/fixedfl-oat.org crt.sh CT logs: https://crt.sh/?q=%25.fixedfl-oat.org Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=fixedfl-oat.org AlienVault OTX: https://otx.alienvault.com/indicator/domain/fixedfl-oat.org URLhaus: https://urlhaus.abuse.ch/host/fixedfl-oat.org/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-26 17:08:20 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] fixedfl-oat.org was flagged by PhishDestroy as a crypto drainer posing as the legitimate FixedFloat exchange platform. The domain mirrors FixedFloat’s branding to trick visitors into connecting cryptocurrency wallets or entering transaction details, allowing threat actors to drain funds directly or harvest credentials for subsequent theft. This deception is reinforced by identical page titles and SSL certificates issued by Let’s Encrypt, which may lull users into a false sense of security. The domain’s recent creation on March 23, 2026, coupled with its use of Dynadot Inc as the registrar and resolution to IP 176.125.242.151, represents a deliberate attempt to exploit brand recognition in the cryptocurrency space, where trust and urgency are primary vectors for exploitation. PhishDestroy’s investigation reveals this domain remains undetected by 95 VirusTotal scanners, highlighting the challenge of identifying novel or low-signal threats. The absence of blocklist entries further underscores its stealthy deployment, likely aimed at evading reactive defenses. The domain’s short operational lifespan and lack of brand protection alerts suggest it is part of a targeted campaign rather than a long-standing fraud operation. Technical indicators, including the Let’s Encrypt SSL certificate and mirrored page content, are carefully crafted to bypass automated detection mechanisms that rely on reputation or signature-based heuristics. Users who visited fixedfl-oat.org should immediately disconnect any connected cryptocurrency wallets and revoke permissions via their wallet interfaces. Scan connected devices for malware or browser extensions that may have captured credentials or private keys. Report the domain to PhishDestroy and your wallet provider, and avoid interacting with similar-looking URLs. Always verify URLs through official channels—such as FixedFloat’s verified domain or published social media profiles—before entering sensitive information or engaging in transactions. Exercise heightened caution with newly registered domains, especially those mimicking well-known financial services. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260426-8A33F9 Favicon MD5: 55a56916ae9ad44cdb0f8c591c1a8a97 TLS cert SHA-256: d9c0ed0cb81a05d2f8d3a30cb37c32982c95b6e4c2ca59db29179852d2f168ce ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/fixedfl-oat.org/ JSON API: https://api.destroy.tools/v1/check?domain=fixedfl-oat.org Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 157,792 domains (42,435 alive under monitoring, 114,252 confirmed takedowns/dead). Site: https://phishdestroy.io