# PhishDestroy threat dossier — hitfxmarket.net ================================================================ Fetched: 2026-07-27 09:47:09 UTC Canonical: https://phishdestroy.io/domain/hitfxmarket.net/ ## VERDICT ---------------------------------------------------------------- ACTIVE THREAT — multiple warning signs Composite threat score: 58/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 3/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Fortinet, Netcraft AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 158.220.124.22 (FR, Lauterbourg) ASN: AS51167 Contabo GmbH Hosting org: Contabo GmbH Registrar: OwnRegistrar, Inc. Nameservers: ns1.zunxoo.com, ns2.zunxoo.com Registered: 2023-10-17 Expires: 2026-10-17 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE1 Expires: 2026-10-09 Status: INVALID chain Fingerprint: a8e54da7153d0226aba38e3330f018dd3d45e997612951ae94f64775d03a4597 Subject Alternative Names (related infrastructure — often same operator): - cpanel.hitfxmarket.net - ftp.hitfxmarket.net - mail.hitfxmarket.net - webmail.hitfxmarket.net - www.hitfxmarket.net ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2023-10-17 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 07:03:46 UTC (by PhishDestroy tracker) First reported: 2026-07-27 07:19:05 UTC (abuse notice filed) Last verified: 2026-07-27 09:45:13 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa203-7ecb-77eb-9ac6-7a5988c8e020/ URLQuery: https://urlquery.net/report/f7bbc6dc-3264-40ac-8379-31771d8a2bb9 Wayback Machine: https://web.archive.org/web/*/hitfxmarket.net crt.sh CT logs: https://crt.sh/?q=%25.hitfxmarket.net Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=hitfxmarket.net AlienVault OTX: https://otx.alienvault.com/indicator/domain/hitfxmarket.net URLhaus: https://urlhaus.abuse.ch/host/hitfxmarket.net/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 07:05:57 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is hitfxmarket.net a phishing scam? The domain hitfxmarket.net is currently classified as a high‑risk generic phishing site and remains active as of the report date, July 27 2026. Registration data shows the domain was created on October 17 2023 through OwnRegistrar, Inc., indicating a relatively recent establishment that aligns with typical phishing campaign lifecycles. DNS resolution points to the IPv4 address 158.220.124.22, and the authoritative name servers are ns1.zunxoo.com and ns2.zunxoo.com, both of which are hosted by the same provider and have been observed in other malicious infrastructures. The domain appears on one known security blocklist and is specifically blocked by the PhishDestroy service, reinforcing the view that it is being actively used for malicious purposes. VirusTotal analysis reports that three out of ninety‑one scanning engines have flagged the domain, providing independent vendor corroboration of its malicious nature. No additional public threat‑intel sources such as OTX or Safe Browsing entries are cited, so the broader ecosystem visibility is limited to the blocklist and vendor detections. The limited detection count suggests the campaign may be in an early deployment stage or employing techniques that evade many scanners, but the presence of any positive detections underlines a credible threat. Defenders should immediately block DNS resolution for hitfxmarket.net and the associated IP address 158.220.124.22 at perimeter and endpoint layers, and consider adding the domain to internal sinkhole lists. Continuous monitoring of outbound connections to the identified nameservers ns1.zunxoo.com and ns2.zunxoo.com is advised, as changes to the DNS infrastructure could indicate campaign evolution. Because the site’s content has not been publicly analyzed, the exact phishing vectors, credential‑capture pages, or targeted brands remain unknown; threat hunters should prioritize traffic capture and sandbox analysis if any user interaction is observed. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-DDCA29 Favicon MD5: 54955321bceaa588e9fb0a09dc5bae6d TLS cert SHA-256: a8e54da7153d0226aba38e3330f018dd3d45e997612951ae94f64775d03a4597 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/hitfxmarket.net/ JSON API: https://api.destroy.tools/v1/check?domain=hitfxmarket.net Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 204,403 domains (79,827 alive under monitoring, 123,545 confirmed takedowns/dead). Site: https://phishdestroy.io