# PhishDestroy threat dossier — iusdcoin.ink ================================================================ Fetched: 2026-04-30 12:18:19 UTC Canonical: https://phishdestroy.io/domain/iusdcoin.ink/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 54/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/94 security vendors flagged this domain ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 107.151.247.68 (HK, Hong Kong) ASN: AS154321 CORENET CLOUD SDN. BHD. Hosting org: VpsQuan L.L.C Registrar: NameCheap, Inc. Nameservers: dns1.registrar-servers.com, dns2.registrar-servers.com Registered: 2026-04-01 Page title: IUSD Coin ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-07-08 Status: INVALID chain Fingerprint: b06ae0d32115a0ae610592963e7c59089022782111a37674a889d8776245609d Subject Alternative Names (related infrastructure — often same operator): - iusd001.com - www.iusd001.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-01 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-22 21:18:19 UTC (by PhishDestroy tracker) First reported: 2026-04-22 18:19:10 UTC (abuse notice filed) Last verified: 2026-04-23 13:02:05 UTC Neutralised: 2026-04-22 21:59:48 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019db669-3c84-72ec-afe7-ce237c8dcef5/ URLQuery: https://urlquery.net/report/03f5dec3-bc8e-4b94-a166-5ad7d1d8cf37 Wayback Machine: https://web.archive.org/web/*/iusdcoin.ink crt.sh CT logs: https://crt.sh/?q=%25.iusdcoin.ink Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=iusdcoin.ink AlienVault OTX: https://otx.alienvault.com/indicator/domain/iusdcoin.ink URLhaus: https://urlhaus.abuse.ch/host/iusdcoin.ink/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-22 21:18:44 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies iusdcoin.ink as a live crypto-drainer domain that mimics USD Coin to trick visitors into connecting wallets and signing malicious transactions. The site is currently unflagged on VirusTotal despite its active campaign, with 0 detections out of 95 engines at the time of analysis. This domain was registered on April 1, 2026, through NameCheap, Inc., and resolves to 107.151.247.68 using a Let’s Encrypt SSL certificate, all indicators that suggest a hastily deployed but potentially dangerous operation. This threat operates by presenting a fake USD Coin interface to visitors, often reached via social media links or spoofed emails. Once a user connects a cryptocurrency wallet, the site prompts for signature requests that drain tokens directly from the connected wallet without requiring private key exposure. Because the domain is only days old and unflagged, it can evade browser filters and appear legitimate at first glance. The combination of a recent creation date, low detection rate, and active hosting suggests this campaign is still in its early, aggressive phase targeting unsuspecting crypto holders. If you visited iusdcoin.ink or connected your wallet, immediately revoke any permissions granted to the site using your wallet’s “connected apps” or “revoke access” feature. Do not sign any additional transaction requests from this domain. Run a full antivirus scan and consider transferring remaining funds to a new wallet with a different seed phrase. Always verify URLs manually and use PhishDestroy’s real-time scanner before interacting with crypto-related sites. Report the domain immediately to help block its spread and protect others. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260422-0F4C03 Favicon MD5: 01812df71dbe3ecb2c8a0ef626b0f072 TLS cert SHA-256: b06ae0d32115a0ae610592963e7c59089022782111a37674a889d8776245609d ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/iusdcoin.ink/ JSON API: https://api.destroy.tools/v1/check?domain=iusdcoin.ink Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io