# PhishDestroy threat dossier — lunatokens-creator.com ================================================================ Fetched: 2026-05-07 09:32:19 UTC Canonical: https://phishdestroy.io/domain/lunatokens-creator.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 94/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: OKX ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 4/91 security vendors flagged this domain ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.67.183.26 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com Nameservers: arya.ns.cloudflare.com, hank.ns.cloudflare.com Registered: 2026-04-28 Page title: Launch MemeCoins Online HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E7 Expires: 2026-07-27 Status: INVALID chain Fingerprint: 8574e5ce043a9b2355fbe2afd5c81dc7089bbc5af59935575e33cf25a565901e ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-28 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-03 13:05:54 UTC (by PhishDestroy tracker) First reported: 2026-05-03 10:06:54 UTC (abuse notice filed) Last verified: 2026-05-07 10:42:07 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019ded4c-609c-7603-91a1-0264d4cbfe7b/ URLQuery: https://urlquery.net/report/b12ef1dc-341b-4955-b87c-a4001c0be1db Wayback Machine: https://web.archive.org/web/*/lunatokens-creator.com crt.sh CT logs: https://crt.sh/?q=%25.lunatokens-creator.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=lunatokens-creator.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/lunatokens-creator.com URLhaus: https://urlhaus.abuse.ch/host/lunatokens-creator.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-03 13:06:14 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] lunatokens-creator.com has been identified by PhishDestroy as a confirmed crypto drainer site engaged in brand impersonation of OKX, a leading global cryptocurrency exchange. The threat level has been classified as under investigation, indicating active monitoring due to the high-risk nature of the operation. This domain employs deceptive tactics to mimic legitimate OKX services, specifically targeting cryptocurrency users to siphon funds through fraudulent token generation or trading interfaces. The site's behavior aligns with known crypto drainer campaigns, which often lure victims with promises of exclusive token launches, airdrops, or advanced trading tools to trick users into connecting their wallets or entering sensitive information. lunatokens-creator.com exhibits multiple indicators of malicious activity. The domain was registered on April 28, 2026, through PDR Ltd. d/b/a PublicDomainRegistry.com, a registrar frequently observed in fraudulent registrations. It resolves to IP address 172.67.183.26, which is associated with high-risk activities across threat intelligence platforms. Despite having an SSL certificate issued by Let's Encrypt—often exploited by threat actors to appear legitimate—the domain currently shows 0 detections out of 95 engines on VirusTotal, suggesting it has not yet been widely flagged by security vendors. This low detection rate is concerning, as it allows the site to remain operational and accessible to potential victims. The domain’s recent creation and the absence of blocklist entries further indicate its likely involvement in ongoing or emerging fraud campaigns. The risk posed by lunatokens-creator.com is significant, primarily due to its targeted brand impersonation of OKX, a trusted name in the cryptocurrency space. Users who interact with this site risk falling victim to crypto drainer schemes, where their digital assets are illicitly transferred to attacker-controlled wallets. To mitigate this threat, individuals should immediately block the domain lunatokens-creator.com on their network and devices. Additionally, users must verify the authenticity of any cryptocurrency-related website by cross-referencing official OKX domains (e.g., okx.com) and avoiding third-party or unofficial token launch platforms. Cryptocurrency users are strongly advised to enable hardware wallet confirmations for transactions, revoke any suspicious wallet connections, and report fraudulent activity to OKX’s official security channels. Organizations should deploy network-level protections, such as DNS filtering, to prevent access to this domain and similar threats. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260503-272A6A Favicon MD5: 88acea5c99017941a277aa41e4dad5ba TLS cert SHA-256: 8574e5ce043a9b2355fbe2afd5c81dc7089bbc5af59935575e33cf25a565901e ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/lunatokens-creator.com/ JSON API: https://api.destroy.tools/v1/check?domain=lunatokens-creator.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 146,204 domains (58,308 alive under monitoring, 87,635 confirmed takedowns/dead). Site: https://phishdestroy.io