# PhishDestroy threat dossier — karma-exchanger.com ================================================================ Fetched: 2026-06-29 00:58:54 UTC Canonical: https://phishdestroy.io/domain/karma-exchanger.com/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Fake Exchange ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/91 security vendors flagged this domain Flagging vendors: Bfore.Ai PreCrime, Forcepoint ThreatSeeker Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 104.21.83.218 (US, San Francisco) ASN: ASAS13335 CLOUDFLARENET - Cloudflare, Inc., US Hosting org: AS13335 Cloudflare, Inc. Registrar: NameCheap, Inc. Nameservers: harlan.ns.cloudflare.com, wanda.ns.cloudflare.com Registered: 2026-03-03 Expires: 2027-03-03 Page title: Авторизация ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-03-03 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-06-24 21:55:07 UTC (by PhishDestroy tracker) First reported: 2026-06-24 19:58:48 UTC (abuse notice filed) Last verified: 2026-06-29 00:20:41 UTC Neutralised: 2026-06-25 03:04:03 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019efb32-2176-74fd-bb90-2eee421580b7/ URLQuery: https://urlquery.net/report/00759e61-9c48-4516-baac-cfb36a59eb3d Wayback Machine: https://web.archive.org/web/*/karma-exchanger.com crt.sh CT logs: https://crt.sh/?q=%25.karma-exchanger.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=karma-exchanger.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/karma-exchanger.com URLhaus: https://urlhaus.abuse.ch/host/karma-exchanger.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-24 22:04:10 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Domain karma-exchanger.com is currently under forensic review for hosting a cryptocurrency exchange impersonation page designed for fund draining operations. The domain aligns with observed tactics where malicious actors clone legitimate crypto platform interfaces to harvest wallet credentials and initiate unauthorized transfers. There is no evidence at this stage tying the site to a known drainer kit such as AngelDrainer or InfernoDrainer; however, the UI structure and infrastructure footprint suggest specialized abuse of blockchain interaction patterns. Analysis indicates that karma-exchanger.com was registered through NameCheap, Inc. on March 03, 2026 and resolves consistently to IPv4 address 104.21.83.218. The domain leverages Cloudflare’s authoritative nameservers harlan.ns.cloudflare.com and wanda.ns.cloudflare.com, providing anonymity and caching benefits typical of malicious infrastructure. As of the most recent scan, VirusTotal returned 2 out of 95 detection engines flagging the domain, and there is no indication of inclusion in Google Safe Browsing lists or public blocklists at this time. The domain’s recent creation date and absence of historical reputation contribute to its elevated risk profile despite low current detection coverage. The infrastructure remains active and accessible, with no takedown notices issued against the domain or its hosting provider. Given the specificity of the threat—crypto drainer impersonation—and the lack of proactive blocking, users interacting with sites resembling crypto exchange portals should exercise extreme caution. Remaining risk is assessed as moderate to high due to the domain’s fresh registration, low detection coverage, and potential for rapid deployment of updated malware components. Organizations are advised to block inbound and outbound communications to 104.21.83.218 and monitor DNS resolutions to the named domain. Continuous monitoring is recommended as this campaign may expand or adopt additional domains. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260624-062AB8 Favicon MD5: f0206ca33b2af2c1827b775097cfa4f1 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/karma-exchanger.com/ JSON API: https://api.destroy.tools/v1/check?domain=karma-exchanger.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 172,229 domains (14,626 alive under monitoring, 157,073 confirmed takedowns/dead). Site: https://phishdestroy.io