# PhishDestroy threat dossier — html5.joikid.com
================================================================
Fetched: 2026-07-28 22:21:51 UTC
Canonical: https://phishdestroy.io/domain/html5.joikid.com/
## VERDICT
----------------------------------------------------------------
TAKEN DOWN (neutralised)
Composite threat score: 49/100 (PhishDestroy scoring — see methodology below)
## DETECTION EVIDENCE
----------------------------------------------------------------
VirusTotal: 4/91 security vendors flagged this domain
Flagging vendors: BitDefender, G-Data, SOCRadar, Webroot
Public blocklists: listed on 1 independent blocklist
## INFRASTRUCTURE
----------------------------------------------------------------
IP address: 151.101.1.195 (CA, Montreal)
ASN: AS54113 Fastly, Inc.
Hosting org: Fastly, Inc.
Registrar: GoDaddy.com, LLC
Nameservers: ["ns55.domaincontrol.com", "ns56.domaincontrol.com"]
Page title: Page Not Found
HTTP response: 404
## TLS CERTIFICATE
----------------------------------------------------------------
Issuer: Google Trust Services / WR3
Expires: 2026-10-05
Status: INVALID chain
Fingerprint: 93cb0c8fb817d5a0fba0697269260ed0ec40f5c061781d8b4562ce466a849b4b
Subject Alternative Names (related infrastructure — often same operator):
- accelixgames.com
- admin.bjtworks.com
- agencies.influens.fr
- ambulatorio-veterinario-parco-monta.it
- app.dev.mozome.com
- app.elvio.in
- app.medservis.com.tr
- applyconsumer.ezfinanz.com
- applynetworks.com
- appv2-staging.construyo.de
- auth.monitop.nl
- auth.sarver.cc
- auth.wrangle.us
- barstaffrewards.com
- beech-hill.xyz
... +84 more
## ABUSE-REPORT HISTORY (evidence of registrar non-response)
----------------------------------------------------------------
Status: CLOSED — no report required.
This domain was neutralised before the abuse-report cycle could be dispatched — either
the hosting provider / registrar suspended it on their own, the DNS went dead, or the
operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file
for audit but no formal notice was sent.
## TIMELINE
----------------------------------------------------------------
First detected: 2026-07-27 00:03:08 UTC (by PhishDestroy tracker)
Last verified: 2026-07-29 00:20:30 UTC
Neutralised: 2026-07-27 03:27:28 UTC
Current status: taken down (registrar suspended or DNS dead)
## ANALYST NARRATIVE
----------------------------------------------------------------
[Generated: 2026-07-27 00:04:38 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.]
html5.joikid.com Fake Login Page
The domain html5.joikid.com is currently flagged as a high‑risk generic phishing infrastructure. Registration records show the domain was acquired through GoDaddy.com, LLC, and it is served by the nameservers ns55.domaincontrol.com and ns56.domaincontrol.com. HTTP queries to the site return a 301 redirect status, indicating that the server is actively forwarding requests, a technique often used to steer victims to malicious landing pages.
The domain has been added to at least one public security blocklist and is presently listed as blocked by the PhishDestroy service, yet monitoring indicates that the domain remains operational. VirusTotal scans report that four of ninety‑one security vendors have identified the domain as malicious, providing additional corroboration of its threat profile. No public evidence of the page title, SSL certificate details, or hosting IP address is available, and the exact content served at the endpoint has not been disclosed in the current intelligence set.
Because the available data confirms active malicious behavior and the presence on a blocklist, defensive teams should enforce domain‑level blocking for html5.joikid.com, incorporate it into URL filtering policies, and continue to monitor associated DNS queries for signs of further exploitation. Analysts should also request updated scans from sandbox environments to capture any evolving payloads or credential‑harvesting mechanisms that may be hosted behind the observed redirect.
## EVIDENCE HASHES
----------------------------------------------------------------
TLS cert SHA-256: 93cb0c8fb817d5a0fba0697269260ed0ec40f5c061781d8b4562ce466a849b4b
## SCORING METHODOLOGY
----------------------------------------------------------------
Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates:
- VirusTotal positive ratio
- Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus,
CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB)
- Cloaking detection (HTTP 666 or rendering delta between bot and real visitor)
- DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.)
- AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing
- URLScan / URLQuery verdicts
- Brand-impersonation heuristics (DOM analysis of forms, logos, wording)
- Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures)
- Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...)
- Free-TLS vs paid-cert ratio (throwaway infrastructure signal)
- Registrar/hosting abuse history (this registrar's track record)
- Human researcher sign-off (operator takedown team)
A domain present in our database is ALREADY flagged. A low VT count by itself does
NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their
first 7–30 days while actively draining wallets. Always cross-reference the composite
score and the individual indicators above, not just VT.
## CORRECTIONS / APPEALS
----------------------------------------------------------------
Full HTML report: https://phishdestroy.io/domain/html5.joikid.com/
JSON API: https://api.destroy.tools/v1/check?domain=html5.joikid.com
Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%)
Submit a report: https://t.me/PhishDestroy_bot
About PhishDestroy: independent open-source threat-intelligence platform.
Tracked: 208,135 domains (82,977 alive under monitoring, 124,126 confirmed takedowns/dead). Site: https://phishdestroy.io