# PhishDestroy threat dossier — kv1x.com ================================================================ Fetched: 2026-07-27 18:04:04 UTC Canonical: https://phishdestroy.io/domain/kv1x.com/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Fake Airdrop Phishing kit: Airdrop Scam ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 4/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, CRDF, Gridinsoft, SOCRadar URLQuery: 2 detections Public blocklists: listed on 2 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 66.29.141.225 (US, Los Angeles) ASN: AS22612 Namecheap, Inc. Hosting org: Namecheap, Inc. Registrar: NAMECHEAP INC Nameservers: dns1.namecheaphosting.com, dns2.namecheaphosting.com Registered: 2026-04-30 Page title: ZEX Token Airdrops on TRUSTPAD-ETHER, The Exclusive Multi-Chain Airdrops HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Sectigo Limited / Sectigo Public Server Authentication CA DV R36 Expires: 2026-10-30 Status: INVALID chain Fingerprint: afc2793c5659c9104c5bba9918b6d85a51b34e8d5e7991e42a522a25321ff739 Subject Alternative Names (related infrastructure — often same operator): - www.kv1x.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-30 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-30 13:57:41 UTC (by PhishDestroy tracker) Earliest abuse rec: 2026-04-30 10:53:49 UTC — PREDATES current WHOIS registration; retained from a previous registration cycle of the same domain name Last verified: 2026-07-27 16:20:47 UTC Neutralised: 2026-06-06 17:33:16 UTC Current status: taken down (registrar suspended or DNS dead) Note: one or more events above predate the WHOIS creation date. This typically means the same domain name was previously registered, detected, dropped, and then re-registered by a new party. PhishDestroy preserves the full historical record for operator-attribution research even when the underlying infrastructure changes hands. ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019dde03-20c0-714f-b481-be1676ad4744/ URLQuery: https://urlquery.net/report/0583646e-1872-4ec7-8cb5-de6818b8900a Wayback Machine: https://web.archive.org/web/*/kv1x.com crt.sh CT logs: https://crt.sh/?q=%25.kv1x.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=kv1x.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/kv1x.com URLhaus: https://urlhaus.abuse.ch/host/kv1x.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-13 00:27:58 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is kv1x.com a ZEX Airdrop Scam? Analysis indicates that kv1x.com operates as a fake airdrop domain with the page title ZEX Token Airdrops on TRUSTPAD-ETHER, The Exclusive Multi-Chain Airdrops. Registered on April 30, 2026 via NAMECHEAP INC, the domain resolves to IP address 66.29.141.225 located in the US under Namecheap, Inc. hosting. Infrastructure analysis reveals nameservers dns1.namecheaphosting.com and dns2.namecheaphosting.com along with MX records pointing to mx1-hosting.jellyfish.systems at priority 5 and another at priority 10. The domain employs LiteSpeed, Cloudflare, jQuery and cdnjs technologies and holds an SSL certificate issued by Sectigo Limited under Sectigo Public Server Authentication CA DV R36. It maintains an active status with HTTP response 200 and carries a Gridinsoft trust score of 0 out of 100. Detections occur on two security blocklists with blocks from PhishDestroy and ScamSniffer while VirusTotal reports flags from 4 of 91 security vendors. The phishing kit identified is Airdrop Scam. Defenders reviewing this domain should implement blocks based on the IP 66.29.141.225 and associated nameservers to prevent exposure to the ongoing threat. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260430-4F278C TLS cert SHA-256: afc2793c5659c9104c5bba9918b6d85a51b34e8d5e7991e42a522a25321ff739 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/kv1x.com/ JSON API: https://api.destroy.tools/v1/check?domain=kv1x.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 206,467 domains (81,639 alive under monitoring, 123,797 confirmed takedowns/dead). Site: https://phishdestroy.io