# PhishDestroy threat dossier — jywjk.com ================================================================ Fetched: 2026-07-27 15:06:22 UTC Canonical: https://phishdestroy.io/domain/jywjk.com/ ## VERDICT ---------------------------------------------------------------- ACTIVE THREAT — multiple warning signs Composite threat score: 55/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 38.177.143.101 (US, San Jose) ASN: AS398478 PEG TECH INC Hosting org: PEG TECH INC Registrar: Gname.com Pte. Ltd. Nameservers: ["ns1.julydns.com", "ns2.julydns.com"] Page title: 医保24小时套现-医保提取24小时微信-套医保卡中介代办换现平台 HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: TrustAsia Technologies, Inc. / LiteSSL RSA CA 2025 Expires: 2026-10-04 Status: INVALID chain Fingerprint: 1825f21a8a4716ed95e5c6e6805c00cf7e7299d8202edd1e3abc41162d6efb9e Subject Alternative Names (related infrastructure — often same operator): - 0750xh.com - 171356.com - aifu168.com - ase35.com - beautiful-china.com - cqgjl.cn - czkqmr.com - dssyyey.cn - fantijf.com - fizdc.com - frp0311.com - ggqimo.com - gssitu.cn - guojinyiyuan.com - hailuoyun.cn ... +81 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-26 20:03:09 UTC (by PhishDestroy tracker) Last verified: 2026-07-27 16:20:22 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-26 20:04:07 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is jywjk.com a Phishing Site? Analysis indicates that the domain jywjk.com remains active as of 26 July 2026. HTTP requests to the host return a 200 OK response, confirming that a web service is reachable. The domain is registered through Gname.com Pte. Ltd. and uses the nameservers ns1.julydns.com and ns2.julydns.com, which are typical of publicly available DNS services. Reputation checks show that jywjk.com is listed on a single security blocklist and is actively blocked by the PhishDestroy feed, which classifies it as a phishing source. A VirusTotal scan involving 91 antivirus and URL‑reputation engines returned no detections, but the absence of a flag does not constitute evidence of legitimacy and should not be interpreted as a safety guarantee. No additional intelligence such as Safe Browsing alerts, OTX mentions, SSL certificate details, or hosting IP information is currently available. Consequently, the primary observable indicators are the active HTTP endpoint, registrar and nameserver data, inclusion on a blocklist, and the PhishDestroy block. Defenders should continue to block the domain at perimeter and endpoint layers, monitor DNS queries for the associated nameservers, and consider adding the domain to internal allow‑list exceptions only after a thorough manual investigation. Ongoing surveillance is recommended to detect any changes in hosting, SSL deployment, or reputation that could alter the risk posture. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: 1825f21a8a4716ed95e5c6e6805c00cf7e7299d8202edd1e3abc41162d6efb9e ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/jywjk.com/ JSON API: https://api.destroy.tools/v1/check?domain=jywjk.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 205,660 domains (80,832 alive under monitoring, 123,797 confirmed takedowns/dead). Site: https://phishdestroy.io