# PhishDestroy threat dossier — h111o.xyz ================================================================ Fetched: 2026-07-26 14:52:11 UTC Canonical: https://phishdestroy.io/domain/h111o.xyz/ ## VERDICT ---------------------------------------------------------------- ACTIVE THREAT — multiple warning signs Composite threat score: 55/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- Registrar: Gname.com Pte. Ltd. Nameservers: ["ns1.1111343.com", "ns2.1111343.com", "ns3.1111343.com", "ns4.1111343.com"] HTTP response: 200 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-26 10:43:10 UTC (by PhishDestroy tracker) Last verified: 2026-07-26 16:20:25 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-26 10:44:28 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] h111o.xyz phishing site impersonates login portals - avoid Analysis of h111o.xyz on July 26, 2026 identifies the domain as an active phishing endpoint. Registered through Gname.com Pte. Ltd., the site returns HTTP status 200, indicating an operational web server. Infrastructure review shows four nameservers—ns1.1111343.com, ns2.1111343.com, ns3.1111343.com, and ns4.1111343.com—suggesting a dedicated hosting setup rather than a compromised shared host. The domain appears on one security blocklist, though VirusTotal scans by 91 vendors currently show no detections, which does not confirm safety but may reflect delayed signature updates or evasion techniques. No brand, page title, or phishing kit has been confirmed in available data, limiting classification to generic credential-harvesting activity. Defenders should treat h111o.xyz as high-risk until further analysis determines the exact target or payload. Blocking the domain at DNS or proxy level is recommended, alongside monitoring for connections from internal assets. ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/h111o.xyz/ JSON API: https://api.destroy.tools/v1/check?domain=h111o.xyz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 198,198 domains (67,517 alive under monitoring, 129,132 confirmed takedowns/dead). Site: https://phishdestroy.io