# PhishDestroy threat dossier — hoodlink.run ================================================================ Fetched: 2026-07-23 14:48:38 UTC Canonical: https://phishdestroy.io/domain/hoodlink.run/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain Flagging vendors: Forcepoint ThreatSeeker Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 2.24.198.130 (US, Boston) ASN: AS47583 Hostinger International Limited Hosting org: Hostinger US Registrar: GoDaddy.com, LLC Nameservers: ns01.domaincontrol.com, ns02.domaincontrol.com Registered: 2026-07-14 Expires: 2027-07-14 Page title: $LINK — a Legend of Zelda fan coin (unofficial parody) HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE2 Expires: 2026-10-12 Status: INVALID chain Fingerprint: ffa3c2adda5b2b6e3f76364fec5b348f8d297fef8f12706b34ae8d7c54c0f811 Subject Alternative Names (related infrastructure — often same operator): - www.hoodlink.run ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-14 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-22 12:11:19 UTC (by PhishDestroy tracker) First reported: 2026-07-22 10:15:26 UTC (abuse notice filed) Last verified: 2026-07-23 16:20:24 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f894d-154d-75be-95db-4fee5ae92442/ URLQuery: https://urlquery.net/report/a2913669-0c89-434f-88c0-7d2c873d4949 Wayback Machine: https://web.archive.org/web/*/hoodlink.run crt.sh CT logs: https://crt.sh/?q=%25.hoodlink.run Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=hoodlink.run AlienVault OTX: https://otx.alienvault.com/indicator/domain/hoodlink.run URLhaus: https://urlhaus.abuse.ch/host/hoodlink.run/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-22 12:11:50 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] hoodlink.run used for high‑risk generic phishing campaign Analysis of hoodlink.run indicates a newly registered domain (creation date July 14, 2026) that is actively leveraged for a generic phishing operation. The domain is hosted by GoDaddy.com, LLC and resolves to the IPv4 address 2.24.198.130. Nameserver records point to ns01.domaincontrol.com and ns02.domaincontrol.com, both standard GoDaddy name servers, which provides no additional obfuscation. The domain has been listed on three security blocklists and is explicitly blocked by PhishDestroy, MetaMask, and SEAL, confirming that multiple threat‑intelligence feeds recognize it as malicious. VirusTotal reports that the domain was scanned by 95 vendors, with no detections returned at the time of analysis; this lack of detections should not be interpreted as an indication of safety, as the domain continues to appear on active blocklists. No public SSL certificate details, HTTP response codes, page title, or Safe Browsing/OTX entries are available in the current intelligence set, leaving the content and transport‑layer characteristics unverified. Consequently, defenders should treat hoodlink.run as a high‑risk phishing indicator, enforce blocking at the network perimeter, update local and cloud‑based blocklists, and monitor for any future changes to its hosting or detection status. Continued observation of its IP reputation and any emerging vendor detections is recommended to adjust defensive controls promptly. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260722-A0AC62 Favicon MD5: 235e97c39134d81e722a82a5dee934c1 TLS cert SHA-256: ffa3c2adda5b2b6e3f76364fec5b348f8d297fef8f12706b34ae8d7c54c0f811 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/hoodlink.run/ JSON API: https://api.destroy.tools/v1/check?domain=hoodlink.run Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 188,898 domains (58,547 alive under monitoring, 128,729 confirmed takedowns/dead). Site: https://phishdestroy.io