# PhishDestroy threat dossier — iusdcoin.xyz ================================================================ Fetched: 2026-04-30 07:41:47 UTC Canonical: https://phishdestroy.io/domain/iusdcoin.xyz/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 90/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 14/94 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar, Forcepoint ThreatSeeker, Fortinet, G-Data, Kaspersky, LevelBlue, Lionic, Sophos, Webroot ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 107.151.247.17 (HK, Hong Kong) ASN: AS154321 CORENET CLOUD SDN. BHD. Hosting org: VpsQuan L.L.C Registrar: Namecheap Nameservers: ["alexandra.ns.cloudflare.com", "malcolm.ns.cloudflare.com"] Registered: 2026-04-22 Page title: 欢迎,跳转中.... ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-07-14 Status: INVALID chain Fingerprint: 39a3cd318869e10edc14910a0d8f15439da2fc84700a7a3ff7a0f700c18d5298 Subject Alternative Names (related infrastructure — often same operator): - app.iusdcoin.xyz - www.iusdcoin.xyz ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-22 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-22 21:21:30 UTC (by PhishDestroy tracker) Last verified: 2026-04-29 13:40:11 UTC Neutralised: 2026-04-23 03:12:03 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019db66a-0ee7-767e-b74a-b352843c4f34/ Wayback Machine: https://web.archive.org/web/*/iusdcoin.xyz crt.sh CT logs: https://crt.sh/?q=%25.iusdcoin.xyz Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=iusdcoin.xyz AlienVault OTX: https://otx.alienvault.com/indicator/domain/iusdcoin.xyz URLhaus: https://urlhaus.abuse.ch/host/iusdcoin.xyz/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-22 21:23:15 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies iusdcoin.xyz as an active generic phishing domain propagating under the guise of a cryptocurrency service. This domain is a suspected cryptocurrency drainer kit designed to impersonate USDT wallet authentication portals. The page title in Chinese (欢迎,跳转中....) suggests redirection to a localized phishing interface, likely targeting users unfamiliar with English-language scams. No known association with legitimate cryptocurrency brands such as Tether or USDT has been confirmed at this stage. Technical analysis reveals critical indicators: the domain resolves to IP address 107.151.247.17 and was registered on April 01, 2026 through Namecheap. VirusTotal currently shows 0/95 detections, indicating zero AV coverage. The domain uses a valid Let's Encrypt SSL certificate, increasing trust perception. Google Safe Browsing (GSB) status remains unflagged, and no blocklist entries have been recorded as of the latest scan. The seed identifier 764c6a confirms this as a tracked but unmitigated threat. The campaign remains active and undetected across major security platforms. Immediate action is required: users should avoid accessing iusdcoin.xyz and block the IP 107.151.247.17 at the network perimeter. Organizations are advised to integrate this domain and IP into firewall and DNS blocklists. While current risk is elevated due to zero detections, the combination of recent registration, Chinese-language lure, and drainer kit behavior signals high potential for financial theft. Continuous monitoring and proactive blocking are essential to prevent victimization. [Updates since narrative was generated:] - VirusTotal detections: now 14/94 (narrative was written when count was lower) ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: b443025f50cea81585e172370ffa0e7f TLS cert SHA-256: 39a3cd318869e10edc14910a0d8f15439da2fc84700a7a3ff7a0f700c18d5298 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/iusdcoin.xyz/ JSON API: https://api.destroy.tools/v1/check?domain=iusdcoin.xyz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io