# PhishDestroy threat dossier — meme-launch.pages.dev ================================================================ Fetched: 2026-05-04 18:37:38 UTC Canonical: https://phishdestroy.io/domain/meme-launch.pages.dev/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 70/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.66.44.150 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: Cloudflare, Inc. Nameservers: annalise.ns.cloudflare.com, quinton.ns.cloudflare.com Registered: 2026-04-27 Page title: Fee Distribution Portal HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E7 Expires: 2026-07-17 Status: INVALID chain Fingerprint: db62b220341eb1fc02717fe172e6a3ee0b921237dee3d14df085b81640281ca4 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-27 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-27 05:49:09 UTC (by PhishDestroy tracker) Last verified: 2026-04-29 07:40:12 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019dccd5-64b0-760f-b529-ad1245dd4307/ Wayback Machine: https://web.archive.org/web/*/meme-launch.pages.dev crt.sh CT logs: https://crt.sh/?q=%25.meme-launch.pages.dev Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=meme-launch.pages.dev AlienVault OTX: https://otx.alienvault.com/indicator/domain/meme-launch.pages.dev URLhaus: https://urlhaus.abuse.ch/host/meme-launch.pages.dev/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-27 05:49:38 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies meme-launch.pages.dev as an active cryptocurrency giveaway scam posing under the guise of a meme token launch event. This domain is engineered to deceive users into connecting their cryptocurrency wallets under the false pretense of receiving free tokens, after which attackers harvest private keys or initiate unauthorized transfers. The site leverages the trusted Cloudflare infrastructure—specifically resolving to IP 172.66.44.150 and utilizing a Let's Encrypt SSL certificate—to appear legitimate and evade initial scrutiny by both users and automated detection systems. The technical risk profile of meme-launch.pages.dev remains concerning despite currently having 0 detections on VirusTotal (0/95 engines). This indicates the site has not yet been flagged by mainstream security vendors, making it more likely to bypass browser warnings and reach potential victims. The domain is registered through Cloudflare, Inc., a legitimate registrar that also provides malicious actors with anonymity and infrastructure reliability. While the exact creation date is not provided, the use of .pages.dev—a domain space often associated with rapid, temporary project deployments—suggests this may be a short-lived campaign intended for quick exploitation before takedown. The absence of detections, combined with active hosting on a reputable CDN, highlights a sophisticated, opportunistic threat that relies on user trust and timing rather than overt malware. Users who have visited meme-launch.pages.dev should immediately disconnect any connected cryptocurrency wallets and revoke permissions granted to unknown or suspicious websites. Scan devices for malware using updated antivirus tools and consider rotating wallet credentials and private keys. Report the domain to your browser’s safe browsing program and to threat intelligence platforms such as Google Safe Browsing or PhishTank. Avoid interacting with any pop-ups or prompts requesting wallet connections, seed phrases, or private key input. Proactively monitor on-chain activity for unauthorized transactions. Remain cautious of unsolicited links promising free tokens or exclusive launches, especially those hosted on cloud platforms with generic subdomains. [Updates since narrative was generated:] - WHOIS creation date: 2026-04-27 ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: db62b220341eb1fc02717fe172e6a3ee0b921237dee3d14df085b81640281ca4 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/meme-launch.pages.dev/ JSON API: https://api.destroy.tools/v1/check?domain=meme-launch.pages.dev Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 145,644 domains (56,174 alive under monitoring, 89,208 confirmed takedowns/dead). Site: https://phishdestroy.io