# mahjong5000.rest — SUSPICIOUS > PhishDestroy flags mahjong5000.rest as a generic phishing site pushing a crypto drainer; VirusTotal shows 0/95 detections. Avoid clicking any links. ## Summary PhishDestroy identifies mahjong5000.rest as a recently activated domain weaponized to steal cryptocurrency from unsuspecting players. This domain was flagged by PhishDestroy after VirusTotal recorded zero detections out of 95 engines, despite the site’s registration date of January 28, 2026. The site is hosted on the IP 104.21.51.148 and uses an SSL certificate issued by Google Trust Services, while being registered through NAMECHEAP INC, a tactic often used to lend false legitimacy to malicious pages. If you visited mahjong5000.rest, disconnect any wallets immediately, revoke any connected permissions, and scan your devices for malware. Report the domain to your wallet provider and avoid re-engaging with the site until authorities or security teams confirm its clean status. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-01-28 15:12:46 - Registrar: NAMECHEAP INC - IP: 104.21.51.148 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/63c6dd21-01b0-4db1-b73d-9a4350489615 - PhishDestroy: https://phishdestroy.io/domain/mahjong5000.rest/ - LLM endpoint: https://phishdestroy.io/domain/mahjong5000.rest/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/mahjong5000.rest/ Last updated: 2026-03-24