# PhishDestroy threat dossier — home-jupittarcdn.wixstudio.com ================================================================ Fetched: 2026-06-28 22:33:22 UTC Canonical: https://phishdestroy.io/domain/home-jupittarcdn.wixstudio.com/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 60/100 (PhishDestroy scoring — see methodology below) Targeted brand: Jupiter ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 3/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Cluster25, Gridinsoft Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- Registrar: GoDaddy.com, LLC Nameservers: ["dns1.p08.nsone.net", "dns2.p08.nsone.net", "dns3.p08.nsone.net", "dns4.p08.nsone.net"] Registered: 2026-06-08 Page title: Jupiter Swap®® | Trading™ Platform®® ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-06-08 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-06-09 05:31:23 UTC (by PhishDestroy tracker) First reported: 2026-06-15 00:27:29 UTC (abuse notice filed) Last verified: 2026-06-29 00:20:41 UTC Neutralised: 2026-06-09 06:27:53 UTC Current status: taken down (registrar suspended or DNS dead) ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-26 01:26:02 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] This domain, home-jupittarcdn.wixstudio.com, poses a significant risk of brand impersonation. It attempts to mimic the legitimate Jupiter brand, which is known for its trading platform, to deceive users into sharing sensitive information or conducting unauthorized transactions. Visiting such a site can lead to financial losses, identity theft, and other forms of cyber fraud. Analysis indicates that home-jupittarcdn.wixstudio.com was created on June 08, 2026, and is currently offline. The domain is registered through GoDaddy.com, LLC, and has been flagged by 3 out of 95 security vendors on VirusTotal. The page title, 'Jupiter Swap®® | Trading™ Platform®®,' closely resembles the genuine Jupiter platform, enhancing the likelihood of user confusion. The site employs technologies such as Wix, React, and Google Cloud, which are commonly used by legitimate websites but can also be leveraged by threat actors to create convincing impersonations. The presence of HSTS and Google Cloud CDN suggests an attempt to appear more secure and credible. Additionally, the SSL certificate is issued by Let's Encrypt, a trusted certificate authority, which can further deceive users into believing the site is legitimate. The domain is listed on three security blocklists: PhishDestroy, PhishingArmy, and OISD, indicating a high level of suspicion among cybersecurity professionals. If a user has visited home-jupittarcdn.wixstudio.com, they should immediately take several precautions to ensure their safety. First, users should check their financial accounts and credit reports for any unauthorized activity. They should also run a full system scan using updated antivirus software to detect any malware that may have been installed. Users should change passwords for their online accounts, especially those related to financial services, and enable two-factor authentication (2FA) wherever possible. It is advisable to report the incident to their bank or financial institution and to the official Jupiter support team. Users should also monitor their email and phone for any suspicious communications that may be part of a follow-up phishing campaign. Finally, staying informed about common phishing tactics and regularly updating security practices can help prevent future incidents. ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/home-jupittarcdn.wixstudio.com/ JSON API: https://api.destroy.tools/v1/check?domain=home-jupittarcdn.wixstudio.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 172,124 domains (14,551 alive under monitoring, 157,073 confirmed takedowns/dead). Site: https://phishdestroy.io