# PhishDestroy threat dossier — keyspeed-items.netlify.app ================================================================ Fetched: 2026-07-29 16:20:15 UTC Canonical: https://phishdestroy.io/domain/keyspeed-items.netlify.app/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 87/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain Flagging vendors: LevelBlue Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 63.176.8.218 (DE, Frankfurt am Main) ASN: AS16509 Amazon.com, Inc. Hosting org: AWS EC2 (eu-central-1) Registrar: Netlify Nameservers: NS_NOT_FOUND Page title: Speed Keyboard Escape · Free Items & Boosts HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: DigiCert Inc / DigiCert Global G2 TLS RSA SHA256 2020 CA1 Expires: 2027-03-19 Status: INVALID chain Fingerprint: bc3a8134c21a842e64ea34d488826dd2ba50f59a3bcbaed1e6b71a4242de1478 Subject Alternative Names (related infrastructure — often same operator): - netlify.app ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-22 17:19:27 UTC (by PhishDestroy tracker) Last verified: 2026-07-29 16:20:30 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f8a68-303b-7454-9aea-ce02e2d09283/ Wayback Machine: https://web.archive.org/web/*/keyspeed-items.netlify.app crt.sh CT logs: https://crt.sh/?q=%25.keyspeed-items.netlify.app Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=keyspeed-items.netlify.app AlienVault OTX: https://otx.alienvault.com/indicator/domain/keyspeed-items.netlify.app URLhaus: https://urlhaus.abuse.ch/host/keyspeed-items.netlify.app/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-22 17:19:38 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is keyspeed-items.netlify.app a phishing site? Analysis indicates that keyspeed-items.netlify.app is a Netlify‑hosted site that has been flagged by at least one anti‑phishing repository. The domain was registered through Netlify’s automated registration service; no separate registrar information is available. DNS resolution points to the IPv4 address 63.176.8.218, which is part of Netlify’s public hosting range. The domain appears on the PhishDestroy blocklist, and PhishDestroy currently lists the domain as active, confirming that the listing is not a historic artifact. No additional blocklists, Safe Browsing entries, or Open Threat Exchange (OTX) reports have been observed for the domain, and no public SSL certificate details or HTTP response codes have been disclosed in the available intelligence. Consequently, the presence of a valid TLS certificate, the HTTP status code returned by the server, and any page‑title metadata remain unknown. The limited evidence suggests a phishing‑related campaign, but the precise target, lure technique, or malicious payload cannot be determined from the current data set. The lack of further telemetry – such as URL‑based detections, sandbox analysis, or user‑reporting – creates uncertainty about the scale of the operation and the specific credentials or personal information being harvested. Defenders should treat the domain as malicious until further verification. Recommended actions include adding 63.176.8.218 to network‑level deny lists, blocking any HTTP(S) requests to keyspeed-items.netlify.app at firewalls or proxy devices, and monitoring outbound traffic for attempts to resolve the domain. Security teams should also watch for future listings on additional threat‑intelligence feeds and consider submitting the domain to sandbox services for deeper behavioural analysis. Continuous re‑evaluation is advised, as the domain’s status may evolve. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: bc3a8134c21a842e64ea34d488826dd2ba50f59a3bcbaed1e6b71a4242de1478 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/keyspeed-items.netlify.app/ JSON API: https://api.destroy.tools/v1/check?domain=keyspeed-items.netlify.app Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,485 domains (83,252 alive under monitoring, 109,716 confirmed takedowns/dead). Site: https://phishdestroy.io