# PhishDestroy threat dossier — investpvf.com ================================================================ Fetched: 2026-06-07 15:10:24 UTC Canonical: https://phishdestroy.io/domain/investpvf.com/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users (type: content_divergence) (score: 1/6) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 3/95 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Forcepoint ThreatSeeker, Netcraft Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 216.244.65.50 (US, Tukwila) ASN: AS27323 Wowrack.com Hosting org: Wowrack.com Registrar: Dynadot Inc Nameservers: dns1.geebytesdns.com, dns2.geebytesdns.com, ns1.nezercloud.com, ns2.nezercloud.com Registered: 2025-12-28 Page title: Pvf Investment – Safe investment with Pvf Investment ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-07-28 Status: INVALID chain Fingerprint: b06bb70ddb2893c0456a1a71040db466e9fb2e9ff20c4d843e9e15a6ab548d5b Subject Alternative Names (related infrastructure — often same operator): - www.invest.investpvf.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-12-28 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-15 20:12:42 UTC (by PhishDestroy tracker) First reported: 2026-05-15 17:16:39 UTC (abuse notice filed) Last verified: 2026-06-07 07:08:54 UTC Neutralised: 2026-06-06 17:30:45 UTC Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e2c9e-98b7-712e-a30d-487f1b250132/ URLQuery: https://urlquery.net/report/acd1951a-06ee-4725-9f1b-f90678a7752f Wayback Machine: https://web.archive.org/web/*/investpvf.com crt.sh CT logs: https://crt.sh/?q=%25.investpvf.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=investpvf.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/investpvf.com URLhaus: https://urlhaus.abuse.ch/host/investpvf.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-15 20:13:41 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies investpvf.com as a live crypto drainer scam designed to trick users into connecting cryptocurrency wallets or entering seed phrases. This domain mimics legitimate investment platforms to steal digital assets, posing a severe risk to cryptocurrency holders seeking passive income opportunities. The threat actor leverages urgency and perceived legitimacy to deceive victims into authorizing malicious transactions or divulging sensitive wallet credentials. This domain was flagged by security vendors with a VirusTotal detection ratio of 3 out of 95 engines, indicating limited but concerning recognition of its malicious nature. Registered through Dynadot Inc on December 28, 2025, the domain resolves to IP address 216.244.65.50 and utilizes a Let's Encrypt SSL certificate to appear trustworthy. Despite its recent creation, the low but nonzero detection rate suggests this scam is actively distributing and evading immediate blocklists. Users who visited investpvf.com should immediately disconnect any connected wallets, revoke any unauthorized approvals, and transfer remaining funds to a secure wallet. Scan devices for malware, change passwords if credentials were entered, and report the domain to security platforms like PhishDestroy or Google Safe Browsing. Avoid interacting with any prompts or requests on this site, as it is a confirmed crypto drainer with elevated risk of financial theft. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260515-E0D7F2 Favicon MD5: 1ead6e0341945604b0a6d328b9554e67 TLS cert SHA-256: b06bb70ddb2893c0456a1a71040db466e9fb2e9ff20c4d843e9e15a6ab548d5b ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/investpvf.com/ JSON API: https://api.destroy.tools/v1/check?domain=investpvf.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 157,787 domains (42,440 alive under monitoring, 114,247 confirmed takedowns/dead). Site: https://phishdestroy.io