# PhishDestroy threat dossier — maixys.us.cc ================================================================ Fetched: 2026-07-21 11:09:54 UTC Canonical: https://phishdestroy.io/domain/maixys.us.cc/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Credential Phishing ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, G-Data URLQuery: 2 detections Public blocklists: listed on 2 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 43.133.41.74 (SG, Singapore) ASN: AS132203 Tencent Building, Kejizhongyi Avenue Hosting org: Aceville Pte.ltd Registrar: Gname.com Pte. Ltd. Nameservers: a.rsp-dns.com, b.rsp-dns.com, ns1.domainnamens.com, ns2.domainnamens.com Registered: 2006-04-07 Expires: 2032-04-07 Page title: Maxis: Postpaid Plan, Home Internet and More | Telco Company HTTP response: 302 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE1 Expires: 2026-10-18 Status: INVALID chain Fingerprint: 76f32a7e9376dae028cf283a21f378f8ba6dc1e094a07fee5f3fe6f7cd0dfa36 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2006-04-07 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-20 14:54:14 UTC (by PhishDestroy tracker) First reported: 2026-07-20 12:56:55 UTC (abuse notice filed) Last verified: 2026-07-21 12:27:44 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f7f95-8378-72df-b1ee-5940b1e0e6e3/ URLQuery: https://urlquery.net/report/3851c46d-e78c-41a8-bbb3-7cf3a2c78770 Wayback Machine: https://web.archive.org/web/*/maixys.us.cc crt.sh CT logs: https://crt.sh/?q=%25.maixys.us.cc Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=maixys.us.cc AlienVault OTX: https://otx.alienvault.com/indicator/domain/maixys.us.cc URLhaus: https://urlhaus.abuse.ch/host/maixys.us.cc/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-20 14:55:40 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] maixys.us.cc Credential Harvesting Site – High Risk Alert Analysis indicates that the domain maixys.us.cc is actively used in a credential harvesting campaign. The domain resolves to the IPv4 address 43.133.41.74 and has been registered since 07 April 2006 through Gname.com Pte. Ltd. Its DNS configuration includes four name servers (a.rsp-dns.com, b.rsp-dns.com, ns1.domainnamens.com, ns2.domainnamens.com), suggesting the use of multiple authoritative providers to increase resilience. The domain appears on a single security blocklist and is currently blocked by the PhishDestroy service, confirming that at least one reputable sinkhole has identified it as malicious. VirusTotal scans show that two out of ninety‑five security vendors flagged the domain, providing independent corroboration of its malicious nature. No additional evidence such as SSL certificate details, HTTP response codes, page title, or brand targeting is available in the supplied intelligence, leaving the exact content and lure technique unconfirmed. The lack of public page analysis means defenders cannot rely on content‑based signatures; instead, infrastructure‑based controls should be prioritized. Recommendations include adding maixys.us.cc and its resolved IP 43.133.41.74 to network deny lists, monitoring DNS queries for the listed name servers, and ensuring that email filters block any messages containing URLs that resolve to this domain. Continuous re‑evaluation is advised, as further reconnaissance may reveal additional indicators of compromise. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260720-4DB6D1 Favicon MD5: 9254ea2965d67e33a7cd6955cf3c7ac8 TLS cert SHA-256: 76f32a7e9376dae028cf283a21f378f8ba6dc1e094a07fee5f3fe6f7cd0dfa36 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/maixys.us.cc/ JSON API: https://api.destroy.tools/v1/check?domain=maixys.us.cc Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 187,516 domains (57,259 alive under monitoring, 128,610 confirmed takedowns/dead). Site: https://phishdestroy.io