# PhishDestroy threat dossier — megasmartrade.live ================================================================ Fetched: 2026-04-22 09:46:09 UTC Canonical: https://phishdestroy.io/domain/megasmartrade.live/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 76/100 (PhishDestroy scoring — see methodology below) Scam classification: Fake Exchange ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 6/94 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, CyRadar, Fortinet, Netcraft, SOCRadar ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.93.120.110 (US, Lenoir) ASN: AS393960 Host4Geeks LLC Hosting org: Host4Geeks LLC Registrar: Dynadot Inc Nameservers: ns1.spantrix.com, ns2.spantrix.com, ns3.spantrix.com Registered: 2026-04-04 Expires: 2027-04-01 Page title: Meta Smart Trade ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-06-30 Status: INVALID chain Fingerprint: e3eeb862903665e77285fcf85d463d95829d45ca21b39a24e0cd9f43bad7f032 Subject Alternative Names (related infrastructure — often same operator): - megasmartrade.live.smartmetrading.live - www.megasmartrade.live.smartmetrading.live ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-04 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-04 15:30:11 UTC (by PhishDestroy tracker) Earliest abuse rec: 2026-04-04 12:37:32 UTC — PREDATES current WHOIS registration; retained from a previous registration cycle of the same domain name Last verified: 2026-04-22 01:40:29 UTC Neutralised: 2026-04-05 17:52:03 UTC Current status: taken down (registrar suspended or DNS dead) Note: one or more events above predate the WHOIS creation date. This typically means the same domain name was previously registered, detected, dropped, and then re-registered by a new party. PhishDestroy preserves the full historical record for operator-attribution research even when the underlying infrastructure changes hands. ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019d5875-993c-71ee-ad1b-82c3d7911c6a/ URLQuery: https://urlquery.net/report/05303253-07de-40f6-b4fa-ab9dc9a43636 Wayback Machine: https://web.archive.org/web/*/megasmartrade.live crt.sh CT logs: https://crt.sh/?q=%25.megasmartrade.live Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=megasmartrade.live AlienVault OTX: https://otx.alienvault.com/indicator/domain/megasmartrade.live URLhaus: https://urlhaus.abuse.ch/host/megasmartrade.live/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-04 15:38:30 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies megasmartrade.live as an active crypto drainer impersonating legitimate trading platforms to siphon cryptocurrency assets from unsuspecting users. This domain was flagged under the generic_phishing threat type and remains unblocked by most antivirus engines, presenting a critical risk to crypto investors who may interact with its fraudulent interfaces. The domain mimics professional trading services to deceive victims into connecting wallets or entering seed phrases, leveraging urgency and sophisticated UI elements to bypass initial scrutiny. Technical analysis reveals the domain resolves to IP 172.93.120.110 and utilizes a Let's Encrypt SSL certificate to appear legitimate, while its recent registration through Dynadot Inc (April 01, 2026) suggests a freshly deployed operation prioritizing short-lived campaigns. This crypto drainer employs multiple evasion techniques to evade detection, including low VirusTotal prevalence (0/95 detections) and rapid infrastructure changes typical of bulletproof hosting providers. The domain's creation date aligns with a surge in fake trading platforms targeting altcoin investors, exploiting the lack of rigorous domain validation in crypto ecosystems. Analysis of the registrar (Dynadot Inc) shows no historical associations with crypto phishing campaigns, indicating a potentially compromised or newly abused registrar account. While the SSL certificate adds superficial legitimacy, it does not guarantee safety, as Let's Encrypt certificates are freely available and often misused in phishing campaigns. The absence of blocklist presence (as of current intelligence) highlights the domain's novelty but should not be interpreted as a clean bill of health. Users who visited megasmartrade.live should immediately revoke any connected wallet permissions via blockchain explorers or wallet interfaces, as crypto drainers often operate by exfiltrating private keys or transaction approvals. Do not enter seed phrases, private keys, or wallet passwords on this domain, even if prompted for 'verification' or 'security checks.' If assets were drained, file reports with relevant blockchain forensic teams (e.g., Chainalysis) and local cybercrime units while documenting transaction hashes. Monitor wallet addresses for unauthorized transactions and consider transferring remaining funds to a cold storage solution. Always verify domains against curated threat databases before engaging with crypto platforms, and prioritize exchanges/apps with two-factor authentication and withdrawal whitelists. [Updates since narrative was generated:] - VirusTotal detections: now 6/94 (narrative was written when count was lower) ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260404-99A915 Favicon MD5: 3909fe5c629f3b195740867a19ef2f1d TLS cert SHA-256: e3eeb862903665e77285fcf85d463d95829d45ca21b39a24e0cd9f43bad7f032 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/megasmartrade.live/ JSON API: https://api.destroy.tools/v1/check?domain=megasmartrade.live Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io