# PhishDestroy threat dossier — machallengers.pro ================================================================ Fetched: 2026-04-22 12:37:46 UTC Canonical: https://phishdestroy.io/domain/machallengers.pro/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 82/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 7/94 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, CyRadar, Ermes, G-Data, Gridinsoft, Sophos ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.67.195.107 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com Nameservers: ["carl.ns.cloudflare.com", "pola.ns.cloudflare.com"] Registered: 2026-04-17 Expires: 2027-04-05 Page title: Global | eSports and Gaming Community HTTP response: 403 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E8 Expires: 2026-07-04 Status: INVALID chain Fingerprint: 8cfa7c8899273ef72be55399711cb6bb8391eb39857831cda793766fe8365c06 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-17 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-17 17:12:40 UTC (by PhishDestroy tracker) Earliest abuse rec: 2026-04-17 14:13:37 UTC — PREDATES current WHOIS registration; retained from a previous registration cycle of the same domain name Last verified: 2026-04-21 16:10:26 UTC Current status: ACTIVE / observable Note: one or more events above predate the WHOIS creation date. This typically means the same domain name was previously registered, detected, dropped, and then re-registered by a new party. PhishDestroy preserves the full historical record for operator-attribution research even when the underlying infrastructure changes hands. ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019d9bc8-7d66-70b8-97da-0c7982571864/ URLQuery: https://urlquery.net/report/786a4ad7-3946-4602-a22b-d36ae65a257f Wayback Machine: https://web.archive.org/web/*/machallengers.pro crt.sh CT logs: https://crt.sh/?q=%25.machallengers.pro Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=machallengers.pro AlienVault OTX: https://otx.alienvault.com/indicator/domain/machallengers.pro URLhaus: https://urlhaus.abuse.ch/host/machallengers.pro/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-17 17:13:04 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies machallengers.pro as a crypto drainer phishing site actively stealing cryptocurrency from unsuspecting users. This domain mimics legitimate crypto platforms to trick victims into connecting wallets and approving fraudulent transactions. Attackers leverage fake trading interfaces or 'airdrops' to harvest private keys or drain wallets directly. Anyone who has visited this site should assume their wallet may be compromised. This domain was flagged by 2 out of 95 VirusTotal security vendors. It was registered through PDR Ltd. d/b/a PublicDomainRegistry.com on April 5, 2026. The site resolves to IP address 172.67.195.107 and is protected by a Let’s Encrypt SSL certificate. The recent creation date and low detection rate suggest this is a newly deployed threat infrastructure. The SSL certificate provides a false sense of legitimacy, while the low VirusTotal score indicates limited widespread awareness among security tools. If you visited machallengers.pro, immediately revoke any wallet connections and disconnect the site from your wallet interface. Do not enter any private keys, seed phrases, or wallet passwords. Transfer remaining funds to a new, secure wallet. Scan your device with updated antivirus software and consider using hardware wallets for future transactions. Report the domain to your wallet provider and file a complaint with relevant authorities. Avoid all links or ads related to this domain—treat it as actively malicious and block it at the network level. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260417-F9532D Favicon MD5: fd88fb39950901fff944d35e7e4777ff TLS cert SHA-256: 8cfa7c8899273ef72be55399711cb6bb8391eb39857831cda793766fe8365c06 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/machallengers.pro/ JSON API: https://api.destroy.tools/v1/check?domain=machallengers.pro Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io