# PhishDestroy threat dossier — hxyl03.com ================================================================ Fetched: 2026-07-29 22:16:01 UTC Canonical: https://phishdestroy.io/domain/hxyl03.com/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 74/100 (PhishDestroy scoring — see methodology below) Scam classification: Credential Phishing ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 8/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET, Fortinet, G-Data, SOCRadar AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 156.224.57.196 (HK, Hong Kong) ASN: AS137951 ASLINE LIMITED Hosting org: Arosscloud INC Registrar: Realtime Register B.V. Nameservers: ["ns1.domainnamedns.com", "ns2.domainnamedns.com"] Page title: 华信娱乐免费下载-华信娱乐app下载2026最新版v7.15.13 安卓版 HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-10-01 Status: INVALID chain Fingerprint: ce2266b7827a55167af78217516b18b8e3173b7d79ff3caf73bfde4015680e20 Subject Alternative Names (related infrastructure — often same operator): - 99uu4100.com - 99uu987.com - gkxcp.com - hgyl1111.com - hgyl2.com - hgyl3.com - hgyl5.com - hgyl6.com - hxyl01.com - hxyl02.com - hxyl04.com - hxyl9999.com - kxcp001.com - kxcp101.com - kxcp345.com ... +83 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-26 14:33:09 UTC (by PhishDestroy tracker) Last verified: 2026-07-29 20:13:36 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-26 14:34:10 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] hxyl03.com Credential Harvesting Site – High Risk Analysis of hxyl03.com shows it is currently active and serving HTTP 200 responses, indicating a live web presence. The domain was registered through Realtime Register B.V. and uses the nameservers ns1.domainnamedns.com and ns2.domainnamedns.com, which are typical of domains that rely on third‑party DNS services. The site has been blocked by the PhishDestroy feed and appears on one additional security blocklist, confirming that at least one threat intelligence source has taken mitigation action. VirusTotal scans report that eight of ninety‑one security vendors have flagged the domain, providing modest but notable detection across multiple engines. No public page title, SSL certificate details, or hosting IP address are disclosed in the available intelligence, leaving the underlying infrastructure partially opaque. Defenders should prioritize adding hxyl03.com to outbound and inbound URL filtering rules, especially for users accessing corporate email or authentication portals, and ensure that web proxies or secure web gateways enforce blocklist entries that reference the domain. Continuous monitoring of DNS queries for the listed nameservers can reveal additional sub‑domains or related activity. Because the domain is still serving content, threat hunters should consider active probing in a controlled environment to capture any credential‑stealing forms or payloads that may be delivered to unsuspecting victims. Organizations employing multi‑factor authentication should verify that any login attempts originating from hxyl03.com are rejected, and incident response teams should be prepared to investigate any credential exposure reports that reference this domain. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 4622610034c9ac46f7434392cfa14b4c TLS cert SHA-256: ce2266b7827a55167af78217516b18b8e3173b7d79ff3caf73bfde4015680e20 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/hxyl03.com/ JSON API: https://api.destroy.tools/v1/check?domain=hxyl03.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,509 domains (83,162 alive under monitoring, 109,831 confirmed takedowns/dead). Site: https://phishdestroy.io