# PhishDestroy threat dossier — jenepe.xyz ================================================================ Fetched: 2026-06-30 11:53:50 UTC Canonical: https://phishdestroy.io/domain/jenepe.xyz/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users (type: content_divergence) (score: 1/6) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 12/91 security vendors flagged this domain AlienVault OTX: 1 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.97.3 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: CloudFlare, Inc. Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED !!! REGISTRAR INTEGRITY ALERT — NiceNIC !!! NiceNIC International: over 90% of its registered domains are associated with illegal content; documented systematic abuse-report non-response. Primary sources: https://phishdestroy.io/nicenic-real https://phishdestroy.io/nicenic-verdict Nameservers: lauryn.ns.cloudflare.com, leland.ns.cloudflare.com Registered: 2026-06-16 Expires: 2027-06-16 Page title: Messenger ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE1 Expires: 2026-09-15 Status: INVALID chain Fingerprint: 7d2e36a7526bbf6f9f0b9ce152c62304fd55e674d6a236b6ef1cea8782566f09 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-06-16 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-06-28 15:57:15 UTC (by PhishDestroy tracker) First reported: 2026-06-28 17:05:46 UTC (abuse notice filed) Last verified: 2026-06-30 12:20:35 UTC Neutralised: 2026-06-29 00:18:17 UTC Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f0e83-98fb-73da-9a8e-eb8c0f889838/ URLQuery: https://urlquery.net/report/825dbeb3-2978-4dd2-b5b6-12ff5e698c7d Wayback Machine: https://web.archive.org/web/*/jenepe.xyz crt.sh CT logs: https://crt.sh/?q=%25.jenepe.xyz Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=jenepe.xyz AlienVault OTX: https://otx.alienvault.com/indicator/domain/jenepe.xyz URLhaus: https://urlhaus.abuse.ch/host/jenepe.xyz/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-28 18:00:48 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] The current analysis categorizes the domain jenepe.xyz as a potential threat specifically associated with credential theft. The risk level is currently under investigation, indicating that there are ongoing assessments to determine the full extent of its threat. Given its page title, which references 'Messenger,' it appears to impersonate a widely used messaging platform, heightening its risk factor in terms of social engineering attacks. Technical indicators surrounding jenepe.xyz have been thoroughly documented. This domain was created on June 16, 2026, and is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED. It resolves to the IP address 188.114.97.3 and has been observed on one security blocklist, indicating some level of recognition as a threat. Furthermore, an examination conducted via AlienVault OTX shows it has appeared in one threat intelligence pulse. Notably, VirusTotal results indicate a count of 0 detections out of 95 total checks, suggesting that it has not yet been flagged by multiple security appliances, thus posing increased risk to users. To mitigate potential risks associated with credential theft, it is paramount that users maintain vigilance when entering personal information on uncertain domains. They should utilize security tools that provide real-time website reputation assessments and employ browser extensions that alert them to potential phishing sites. Additionally, users should be educated on the attributes of fake websites, including domain age and registration information, to minimize susceptibility to such attacks. Regular monitoring of security blocklists may also help in identifying newly registered malicious domains. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260628-7F0BAB Favicon MD5: ec1057db022c104327e0451eeab338cf TLS cert SHA-256: 7d2e36a7526bbf6f9f0b9ce152c62304fd55e674d6a236b6ef1cea8782566f09 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/jenepe.xyz/ JSON API: https://api.destroy.tools/v1/check?domain=jenepe.xyz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 172,677 domains (12,746 alive under monitoring, 159,341 confirmed takedowns/dead). Site: https://phishdestroy.io