# PhishDestroy threat dossier — jupiterpro.info ================================================================ Fetched: 2026-04-22 19:20:10 UTC Canonical: https://phishdestroy.io/domain/jupiterpro.info/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 62/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Jupiter ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/95 security vendors flagged this domain ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 212.85.6.157 (BR, São Paulo) ASN: AS47583 Hostinger International Limited Hosting org: Hostinger International Limited Registrar: HOSTINGER operations, UAB Nameservers: ns1.dns-parking.com, ns2.dns-parking.com Registered: 2025-05-14 Expires: 2026-05-14 Page title: Home | Jupiter Pro ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-06-08 Status: INVALID chain Fingerprint: d9982fd5095c1d526b0010f56cbf3939e02656e4553dc940cb953570804dfe3e Subject Alternative Names (related infrastructure — often same operator): - www.jupiterpro.info ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-05-14 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-22 15:52:04 UTC (by PhishDestroy tracker) First reported: 2026-04-22 12:55:35 UTC (abuse notice filed) Last verified: 2026-04-22 21:24:39 UTC Neutralised: 2026-04-22 16:43:16 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019db53d-969d-736f-8f62-6abffb5ac7e2/ URLQuery: https://urlquery.net/report/3cccc0e0-cc90-4a96-9c35-62e53e1a0946 Wayback Machine: https://web.archive.org/web/*/jupiterpro.info crt.sh CT logs: https://crt.sh/?q=%25.jupiterpro.info Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=jupiterpro.info AlienVault OTX: https://otx.alienvault.com/indicator/domain/jupiterpro.info URLhaus: https://urlhaus.abuse.ch/host/jupiterpro.info/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-22 15:53:25 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies an active brand-impersonation site using the domain jupiterpro.info to mimic Jupiter and deploy a crypto-draining operation. The page lures visitors with fake offers or urgent updates and, once loaded, silently connects wallets to siphon tokens without permission. Because the domain is freshly registered and still under the radar, users who land here may not notice the theft until after funds vanish, making this a high-risk trap for crypto holders actively engaging with Jupiter-related services. This domain was flagged by PhishDestroy on seed 01ea31. Technical records show jupiterpro.info was created on May 14, 2025, resolves to IP 212.85.6.157, and currently yields 0 detections out of 95 engines on VirusTotal. The site is served over a Let’s Encrypt SSL certificate for a superficial appearance of legitimacy, yet it was registered through HOSTINGER operations, UAB, a common bulletproof provider abused by low-effort scam campaigns. These facts place the threat at “under investigation” status while attackers refine their scripts to evade static detection. If you visited jupiterpro.info — even briefly — disconnect your wallet immediately, revoke any wallet-connect permissions granted to the domain, and move remaining assets to a fresh wallet. Use PhishDestroy’s real-time scanner to verify links before clicking, and never enter seed phrases or private keys on any page linked from unsolicited messages. Stay vigilant: newly registered domains mimicking established brands often appear harmless until the damage is done. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260422-2D13DE Favicon MD5: 2c6678f9296cfcdb886cb9ba88d28d4d TLS cert SHA-256: d9982fd5095c1d526b0010f56cbf3939e02656e4553dc940cb953570804dfe3e ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/jupiterpro.info/ JSON API: https://api.destroy.tools/v1/check?domain=jupiterpro.info Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io