# PhishDestroy threat dossier — js88805.com ================================================================ Fetched: 2026-07-27 13:37:28 UTC Canonical: https://phishdestroy.io/domain/js88805.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 98/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 16/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Google Safe Browsing, Gridinsoft, Kaspersky, Lionic, SOCRadar, Sophos, VIPRE, Webroot AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist Google Safe Browsing: FLAGGED ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 154.89.77.211 (HK, Hong Kong) ASN: AS142286 LUOGELANG (FRANCE) LIMITED Hosting org: CloudFly Net Inc Registrar: TuringSign Inc. d/b/a Cosmotown Nameservers: ["ns1.domainnamedns.com", "ns2.domainnamedns.com"] HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-09-04 Status: INVALID chain Fingerprint: 4bc8be19037d348b0bb0b5d4f3e02a49b526fd52cbd24f4c6a47b2c423c3676a Subject Alternative Names (related infrastructure — often same operator): - js7328.com - js7448.com - js7598.com - js7607.com - js77133.com - js7739.com - js7761.com - js779933.com - js7800.com - js7941.com - js80156.com - js8044.com - js828.xyz - js8297.com - js830830.com ... +83 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-26 19:23:08 UTC (by PhishDestroy tracker) Last verified: 2026-07-27 12:57:22 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-26 19:24:48 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] js88805.com phishing site impersonates brands – high risk alert Analysis conducted on July 26, 2026 identifies js88805.com as an active phishing domain exhibiting multiple indicators of malicious infrastructure. The domain returns an HTTP 200 status, confirming it is currently serving content, though the exact nature of the page remains unconfirmed due to limited forensic analysis. Detection data from VirusTotal indicates that 16 of 91 security vendors have flagged this domain, suggesting a pattern of suspicious behavior recognized by multiple threat intelligence sources. The domain appears on at least one security blocklist, and Google Safe Browsing has classified it under social engineering, further corroborating its association with deceptive practices. Infrastructure analysis reveals the domain was registered through TuringSign Inc., operating as Cosmotown, a registrar frequently observed in phishing campaigns. The nameservers ns1.domainnamedns.com and ns2.domainnamedns.com are consistent with hosting patterns used by threat actors to maintain operational resilience. While the specific brand or service being impersonated is not yet confirmed, the combination of detection flags, blocklist presence, and Safe Browsing classification indicates a high-risk phishing operation. Defenders are advised to treat this domain as actively malicious. Network-level blocking is recommended based on the available evidence, and organizations should monitor for any connections to js88805.com within their environments. Further investigation into associated IP addresses, SSL certificates, and hosting providers may yield additional indicators of compromise. Given the domain's persistence and detection history, it is likely part of a broader phishing infrastructure rather than an isolated incident. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 03324e7ed66de8413aaf4ecac69b2fc8 TLS cert SHA-256: 4bc8be19037d348b0bb0b5d4f3e02a49b526fd52cbd24f4c6a47b2c423c3676a ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/js88805.com/ JSON API: https://api.destroy.tools/v1/check?domain=js88805.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 205,501 domains (80,673 alive under monitoring, 123,797 confirmed takedowns/dead). Site: https://phishdestroy.io