# layendashboand-foundation.com.mx — SUSPICIOUS > PhishDestroy detects crypto drainer layendashboand-foundation.com.mx flagged by 1 of 95 VirusTotal vendors; avoid this fake login impersonating a foundation. ## Summary PhishDestroy identifies the active crypto drainer domain layendashboand-foundation.com.mx impersonating a foundation entity as of March 19, 2026. This domain was flagged by 1 of 95 VirusTotal vendors at the time of analysis and resolves to IP 104.21.62.204. It is registered through AKKY ONLINE SOLUTIONS, S.A. DE C.V. using a Let’s Encrypt SSL certificate and was created on March 19, 2026. Independent threat intelligence sources report zero additional blocklist detections and low trust scores across behavioral and infrastructure analytics. The campaign is currently active and poses an elevated risk due to the presence of a suspected crypto drainer script designed to exfiltrate cryptocurrency wallet credentials and assets. PhishDestroy recommends immediate network and endpoint blocking of this domain and associated IP. Users should avoid interacting with any login pages or wallet connection prompts linked to layendashboand-foundation.com.mx. For verification and real-time alerts, cross-reference this domain using PhishDestroy’s threat intelligence platform. Organizations are advised to update firewall rules, DNS sinkholes, and endpoint protection policies to prevent access to this domain and to conduct user awareness training highlighting the risks of impersonation scams involving charitable or foundation-themed domains. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-19 00:00:00 - Registrar: AKKY ONLINE SOLUTIONS, S.A. DE C.V. - IP: 104.21.62.204 ## Detection Status - VirusTotal: 1 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/bc973826-658b-48b7-9b4f-51b0c5b11c5d - PhishDestroy: https://phishdestroy.io/domain/layendashboand-foundation.com.mx/ - LLM endpoint: https://phishdestroy.io/domain/layendashboand-foundation.com.mx/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/layendashboand-foundation.com.mx/ Last updated: 2026-03-23