# PhishDestroy threat dossier — m.xbull.art ================================================================ Fetched: 2026-04-30 15:57:01 UTC Canonical: https://phishdestroy.io/domain/m.xbull.art/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: WalletConnect ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 7/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar, G-Data, Kaspersky URLQuery: 2 detections ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.67.198.95 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: Gname.com Pte. Ltd. Nameservers: ["ariadne.ns.cloudflare.com", "everton.ns.cloudflare.com"] Registered: 2026-04-27 Page title: XBULL HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-07-07 Status: INVALID chain Fingerprint: b8833597fb8a79e2344a43528136b59aea4b3381b96a1f18480039c34cdeda87 Subject Alternative Names (related infrastructure — often same operator): - xbull.art ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-27 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-27 20:12:15 UTC (by PhishDestroy tracker) Earliest abuse rec: 2026-04-27 17:13:35 UTC — PREDATES current WHOIS registration; retained from a previous registration cycle of the same domain name Last verified: 2026-04-30 18:07:07 UTC Neutralised: 2026-04-29 09:27:45 UTC Current status: taken down (registrar suspended or DNS dead) Note: one or more events above predate the WHOIS creation date. This typically means the same domain name was previously registered, detected, dropped, and then re-registered by a new party. PhishDestroy preserves the full historical record for operator-attribution research even when the underlying infrastructure changes hands. ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019dcfeb-97be-71fc-a8a2-f1a673d2ac79/ URLQuery: https://urlquery.net/report/a75c6cb0-e569-4551-b00f-be13ccb7a313 Wayback Machine: https://web.archive.org/web/*/m.xbull.art crt.sh CT logs: https://crt.sh/?q=%25.m.xbull.art Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=m.xbull.art AlienVault OTX: https://otx.alienvault.com/indicator/domain/m.xbull.art URLhaus: https://urlhaus.abuse.ch/host/m.xbull.art/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-27 20:13:33 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy flags m.xbull.art as an active crypto drainer scam posing as a digital art platform. If you connected a wallet or entered seed phrases, your crypto assets could be drained immediately. This domain was registered on August 15, 2025 through Gname.com Pte. Ltd. and currently hosts its infrastructure on IP 172.67.198.95 with a Google Trust Services SSL certificate. VirusTotal shows 0 detections out of 95 engines, indicating it has flown under the radar but remains a high-risk threat. Crypto drainer sites like m.xbull.art mimic legitimate NFT marketplaces or art platforms to trick users into connecting cryptocurrency wallets. Once connected, malicious scripts automatically drain tokens and NFTs without requiring additional confirmations. The threat is especially severe because blockchain transactions are irreversible, leaving victims with no recovery options. Even a single visit or wallet interaction can result in financial loss within seconds. If you visited m.xbull.art, immediately disconnect and revoke wallet permissions using tools like Revoke.cash or your wallet’s built-in app management. Do not interact with any transactions that may have occurred. Report the domain to your wallet provider and local cybercrime units. Share this warning on crypto communities to prevent others from falling victim. Stay safe: never connect wallets to unknown websites. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260427-B8C4AF Favicon MD5: 9aa390f797194d27a1d0894c5412437e TLS cert SHA-256: b8833597fb8a79e2344a43528136b59aea4b3381b96a1f18480039c34cdeda87 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/m.xbull.art/ JSON API: https://api.destroy.tools/v1/check?domain=m.xbull.art Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io