# PhishDestroy threat dossier — login-axiom.trade ================================================================ Fetched: 2026-07-28 17:16:35 UTC Canonical: https://phishdestroy.io/domain/login-axiom.trade/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Wallet/Seed Phishing Targeted brand: across (and: coinbase, twitter) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 7/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Chong Lua Dao, CRDF, CyRadar, Forcepoint ThreatSeeker, Fortinet, Gridinsoft URLQuery: 2 detections Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.96.3 (US, San Francisco) ASN: ASAS13335 CLOUDFLARENET - Cloudflare, Inc., US Hosting org: AS13335 Cloudflare, Inc. Registrar: NameSilo, LLC !!! REGISTRAR INTEGRITY ALERT — NameSilo !!! NameSilo is a registrar documented by PhishDestroy as (1) publicly lying about received abuse reports, (2) shielding a $20M+ Monero-theft operation (xmrwallet.com) for 10 continuous years, and (3) retaliating against PhishDestroy by getting our X/Twitter account @Phish_Destroy banned after we published the evidence. Researchers/victims must ALWAYS CC compliance@icann.org on every abuse ticket — NameSilo has a track record of later claiming reports were never received. Primary sources: https://phishdestroy.io/namesilo-killed-our-twitter https://phishdestroy.io/xmrwallet-namesilo-exposed Nameservers: ["everton.ns.cloudflare.com", "jo.ns.cloudflare.com"] Registered: 2026-02-27 Expires: 2027-02-25 Page title: Axiom HTTP response: 403 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E7 Expires: 2026-05-26 Status: INVALID chain Fingerprint: 5c5169ed1a54c99baa934160ee2b44270a7ca3929293d134a864824b9e4c59dd ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-02-27 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-02-27 21:24:39 UTC (by PhishDestroy tracker) Earliest abuse rec: 2026-02-27 18:36:57 UTC — PREDATES current WHOIS registration; retained from a previous registration cycle of the same domain name Last verified: 2026-07-28 16:21:08 UTC Current status: ACTIVE / observable Note: one or more events above predate the WHOIS creation date. This typically means the same domain name was previously registered, detected, dropped, and then re-registered by a new party. PhishDestroy preserves the full historical record for operator-attribution research even when the underlying infrastructure changes hands. ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019ca056-9088-71d9-b942-10e6600f0b34/ URLQuery: https://urlquery.net/report/dd2a0cd2-88f2-443d-b0da-c3239284feb1 Wayback Machine: https://web.archive.org/web/*/login-axiom.trade crt.sh CT logs: https://crt.sh/?q=%25.login-axiom.trade Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=login-axiom.trade AlienVault OTX: https://otx.alienvault.com/indicator/domain/login-axiom.trade URLhaus: https://urlhaus.abuse.ch/host/login-axiom.trade/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-26 18:14:16 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] login-axiom.trade: Brand Impersonation Threat Targeting Across This domain is flagged as an active brand impersonation threat designed to deceive users of the Across protocol. Analysis indicates the infrastructure is tailored for credential theft or unauthorized transaction redirection, leveraging the trust associated with the targeted brand. The domain presents a calculated risk to users who may unknowingly interact with it under the false pretense of legitimacy. Infrastructure analysis reveals the following technical indicators: the domain login-axiom.trade was registered through NameSilo, LLC on February 27, 2026, and currently resolves to the IP address 188.114.96.3. At the time of assessment, VirusTotal reported 0 detections out of 95 security engines, suggesting the domain has not yet been widely flagged. However, it appears on three security blocklists, including those maintained by MetaMask, PhishDestroy, and SEAL. The SSL certificate is issued by Let's Encrypt, a common choice for both legitimate and malicious domains. Technologies detected include Cloudflare Browser Insights, Cloudflare, and HTTP/3, which are frequently used to obfuscate hosting origins and enhance performance. To mitigate risks associated with this brand impersonation threat, users should verify domain authenticity by cross-referencing official communications from the Across protocol. Any interaction with login-axiom.trade or similar domains should be avoided, particularly those soliciting credentials or transaction approvals. Network-level protections, such as DNS filtering or endpoint detection rules, should be updated to block access to the domain and its associated IP address. Organizations are advised to monitor for unusual login attempts or transaction patterns that may indicate compromise stemming from this campaign. Proactive measures, including user education on recognizing spoofed domains and enabling multi-factor authentication, are critical to reducing exposure to such threats. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260227-2D6680 TLS cert SHA-256: 5c5169ed1a54c99baa934160ee2b44270a7ca3929293d134a864824b9e4c59dd ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/login-axiom.trade/ JSON API: https://api.destroy.tools/v1/check?domain=login-axiom.trade Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 212,243 domains (86,683 alive under monitoring, 124,530 confirmed takedowns/dead). Site: https://phishdestroy.io