# PhishDestroy threat dossier — iusd001.com ================================================================ Fetched: 2026-04-30 09:07:21 UTC Canonical: https://phishdestroy.io/domain/iusd001.com/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 76/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: WalletConnect ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/94 security vendors flagged this domain ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 107.151.247.68 (HK, Hong Kong) ASN: AS154321 CORENET CLOUD SDN. BHD. Hosting org: VpsQuan L.L.C Registrar: NAMECHEAP INC Nameservers: alexandra.ns.cloudflare.com, malcolm.ns.cloudflare.com Registered: 2026-04-09 Page title: IUSD Coin ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-07-08 Status: INVALID chain Fingerprint: b06ae0d32115a0ae610592963e7c59089022782111a37674a889d8776245609d Subject Alternative Names (related infrastructure — often same operator): - www.iusd001.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-09 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-22 21:21:30 UTC (by PhishDestroy tracker) First reported: 2026-04-22 18:23:30 UTC (abuse notice filed) Last verified: 2026-04-29 13:40:11 UTC Neutralised: 2026-04-23 03:12:03 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019db66c-1264-703c-b8d5-800eaec21458/ URLQuery: https://urlquery.net/report/655ea3c8-eae7-4085-8865-1866714cb642 Wayback Machine: https://web.archive.org/web/*/iusd001.com crt.sh CT logs: https://crt.sh/?q=%25.iusd001.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=iusd001.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/iusd001.com URLhaus: https://urlhaus.abuse.ch/host/iusd001.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-22 21:23:06 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies iusd001.com as a high-risk crypto drainer posing under the guise of an IUSD Coin promotional site. This fraudulent domain is designed to trick cryptocurrency investors into connecting wallets or downloading malicious files, thereby draining funds or stealing credentials under false pretenses. The site mimics legitimate crypto projects to exploit user trust, leveraging urgency and technical-sounding terminology to encourage hasty actions that compromise security. Unlike generic phishing attempts, this threat is specifically engineered for cryptocurrency theft, making it particularly dangerous for users involved in digital asset trading or storage. This domain was flagged due to clear indicators of crypto drainer activity. Registrant details reveal hosting through NAMECHEAP INC, a common provider for fraudulent sites due to weak verification processes. The domain was registered on April 09, 2026, and resolves to IP 107.151.247.68. It operates with an SSL certificate from Let's Encrypt, which, while indicative of HTTPS encryption, does not validate legitimacy. Most critically, VirusTotal currently shows 0/95 detections, meaning no antivirus engines flag it as malicious at this time—a common trait for newly deployed threats. Despite its low detection rate, the site’s deceptive branding and lack of verifiable credentials warrant extreme caution. If you visited iusd001.com, disconnect any connected wallets immediately and revoke permissions through your wallet provider’s security settings. Do not enter any credentials, download files, or interact with transaction prompts. Clear browser cache and cookies, and consider running a malware scan using reputable software. Report the domain to your antivirus provider and block it via hosts file or firewall rules. Verify the legitimacy of any crypto-related website by cross-checking official social media, domain age, and community feedback. Remember: legitimate projects do not rely on recently registered domains with low transparency. [Updates since narrative was generated:] - VirusTotal detections: now 1/94 (narrative was written when count was lower) ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260422-94720F Favicon MD5: b443025f50cea81585e172370ffa0e7f TLS cert SHA-256: b06ae0d32115a0ae610592963e7c59089022782111a37674a889d8776245609d ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/iusd001.com/ JSON API: https://api.destroy.tools/v1/check?domain=iusd001.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io