# PhishDestroy threat dossier — kodeotp.com ================================================================ Fetched: 2026-07-31 02:50:45 UTC Canonical: https://phishdestroy.io/domain/kodeotp.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 6/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Fortinet, Gridinsoft URLQuery: -1 detections AlienVault OTX: 1 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 103.224.212.204 (AU, Beaumaris) ASN: AS133618 Trellian Pty. Limited Hosting org: Trellian Pty. Limited Registrar: Domain Science Kutatasi Szolgaltato Korlatolt Felelossegu Tarsasag Nameservers: ["5579.ns1.abovedomains.com", "5579.ns2.abovedomains.com"] Registered: 2026-05-01 Page title: kodeotp.com HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-06-04 Status: INVALID chain Fingerprint: f0f784ab2e6f2dea3bc50a1bcf95f26bc85e339f855e48989c80a6dbc4a8d4e3 Subject Alternative Names (related infrastructure — often same operator): - 123mkv.cyou - applgift.cyou - assistirfilmesonlines.com - barrelhouse211.com - doodadomains.com.au - e11e.online - echuis-uwe8.shop - entendo.eu - fenrirdogtraining.com - findyourmuse.website - fractures.com.au - fsa2mbsbbank.com - funplex.fun - golubok.org - graindpain.com ... +23 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-01 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-02 01:30:08 UTC (by PhishDestroy tracker) First reported: 2026-06-15 06:36:57 UTC (abuse notice filed) Last verified: 2026-07-31 04:20:50 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-12 18:46:07 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is kodeotp.com a phishing site? The domain kodeotp.com was registered on May 01, 2026 through Domain Science Kutatasi Szolgaltato Korlatolt Felelossegu Tarsasag and is currently active. Its creation date places it among recent registrations often associated with opportunistic phishing campaigns. The sole page title observed is "kodeotp.com", providing no additional context about the site’s purpose or targeted brand. Infrastructure analysis shows the domain resolves to IP address 103.224.212.204, which is geolocated to Australia and attributed to Trellian Pty. Limited. The authoritative nameservers listed are 5579.ns1.abovedomains.com and 5579.ns2.abovedomains.com, both typical of bulk‑hosting services. The site presents a valid Let’s Encrypt certificate, indicating the presence of TLS encryption but offering no indication of legitimacy. Threat intelligence indicates that kodeotp.com appears on one security blocklist and has been blocked by PhishDestroy, confirming that at least one defensive feed has classified it as malicious. The domain is referenced in a single AlienVault OTX pulse, suggesting limited but existing community awareness. Gridinsoft assigns the domain a trust score of 0 out of 100, and VirusTotal returns zero detections out of 95 scanners, reflecting a low detection footprint that is common for newly deployed phishing infrastructure. Defenders should treat kodeotp.com as a high‑confidence phishing indicator. Immediate actions include adding the domain to outbound web filtering rules and DNS blocklists, monitoring DNS queries for the associated IP and nameservers, and instrumenting network telemetry to detect any attempted connections. Given the recent registration and low detection history, continuous re‑evaluation is advised, with periodic checks against threat feeds for any escalation in activity or additional malicious payloads linked to the domain. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: f0f784ab2e6f2dea3bc50a1bcf95f26bc85e339f855e48989c80a6dbc4a8d4e3 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/kodeotp.com/ JSON API: https://api.destroy.tools/v1/check?domain=kodeotp.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 196,186 domains (84,172 alive under monitoring, 26,900 confirmed neutralized). Site: https://phishdestroy.io