# PhishDestroy threat dossier — naopux.com ================================================================ Fetched: 2026-06-26 07:20:34 UTC Canonical: https://phishdestroy.io/domain/naopux.com/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users (type: content_divergence) (score: 2/6) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 18/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, BitDefender, Certego, Chong Lua Dao, CRDF, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Kaspersky, LevelBlue, Lionic, Netcraft, SOCRadar, Sophos, VIPRE URLQuery: 3 detections Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 69.67.173.34 (RO, Bucharest) Hosting org: AS399629 BL Networks Registrar: Fewmoretaps OU d/b/a Trustname.com !!! REGISTRAR INTEGRITY ALERT — Trustname / Fewmoretaps OU !!! Trustname (IANA #4318) is a shell company declaring EUR 120 annual revenue, 1 employee, negative equity, Belarusian ownership. Explicitly advertises itself as 'bulletproof' in its DNS TXT records. Primary source: https://phishdestroy.io/trustname-bulletproof-exposed Nameservers: imani.ns.cloudflare.com, milan.ns.cloudflare.com Registered: 2026-06-08 Expires: 2027-06-08 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: none Status: INVALID chain ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-06-08 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-06-24 14:15:25 UTC (by PhishDestroy tracker) First reported: 2026-06-24 12:31:21 UTC (abuse notice filed) Last verified: 2026-06-26 08:20:34 UTC Neutralised: 2026-06-24 18:19:01 UTC Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019ef98d-172d-759b-9a59-78d3ddfe22d6/ URLQuery: https://urlquery.net/report/9d752a86-5d60-4e11-bf3c-7655d6b6c77d Wayback Machine: https://web.archive.org/web/*/naopux.com crt.sh CT logs: https://crt.sh/?q=%25.naopux.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=naopux.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/naopux.com URLhaus: https://urlhaus.abuse.ch/host/naopux.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-25 19:22:51 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] This domain, naopux.com, is identified as a high-risk phishing site. Analysis indicates that the domain specifically poses a threat by attempting to steal sensitive information such as login credentials and financial data from unsuspecting users. The domain has been flagged by multiple security services for its malicious activities. Infrastructure analysis reveals that naopux.com has been flagged by 18 out of 95 security vendors on VirusTotal, indicating a significant level of concern among the security community. The domain was registered through Fewmoretaps OU d/b/a Trustname.com on June 08, 2026, and resolves to the IP address 69.67.173.34. Additionally, it appears on 4 security blocklists, further confirming its malicious nature. The SSL certificate was issued by Let's Encrypt, which is a common tactic used by phishing sites to appear more legitimate to users. Users who have visited naopux.com are advised to change their passwords and check their account statements for any unauthorized activity. It is recommended to run a full system scan using updated antivirus software and report any suspicious activity to their security teams or service providers. To avoid future phishing attempts, users should verify the URL of websites before entering any sensitive information and be cautious of unsolicited emails or messages that prompt them to click on links. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260624-2A33A9 Favicon MD5: c3d9e7ac8ad834ae3d129c8c7a595a4f ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/naopux.com/ JSON API: https://api.destroy.tools/v1/check?domain=naopux.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 170,057 domains (12,358 alive under monitoring, 157,076 confirmed takedowns/dead). Site: https://phishdestroy.io