# PhishDestroy threat dossier — nextepochmarket.xyz ================================================================ Fetched: 2026-05-04 17:17:24 UTC Canonical: https://phishdestroy.io/domain/nextepochmarket.xyz/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 87/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Investment Scam ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/95 security vendors flagged this domain URLQuery: 1 detections ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.67.135.66 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: Gname.com Pte. Ltd. Nameservers: ruben.ns.cloudflare.com, serenity.ns.cloudflare.com Registered: 2026-05-02 Page title: Nexte: One-Stop Global Investment Platform | Forex | Commodities | Stocks | Indices | Cryptocurrencies | Gold | Oil HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E7 Expires: 2026-07-31 Status: INVALID chain Fingerprint: f8cac2606d2f7749afbe18169f130674b732cb739db6e666da58cce5f5abaaf1 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-02 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-04 16:20:10 UTC (by PhishDestroy tracker) First reported: 2026-05-04 13:24:00 UTC (abuse notice filed) Last verified: 2026-05-04 19:50:03 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019df324-3f8b-703a-a748-4f6837663cb9/ URLQuery: https://urlquery.net/report/e3e6e694-2988-4cb6-ae33-95c5de0bda0e Wayback Machine: https://web.archive.org/web/*/nextepochmarket.xyz crt.sh CT logs: https://crt.sh/?q=%25.nextepochmarket.xyz Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=nextepochmarket.xyz AlienVault OTX: https://otx.alienvault.com/indicator/domain/nextepochmarket.xyz URLhaus: https://urlhaus.abuse.ch/host/nextepochmarket.xyz/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-04 16:21:57 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies nextepochmarket.xyz as an active crypto drainer phishing domain, designed to trick users into unknowingly authorizing malicious cryptocurrency transfers. The site impersonates legitimate crypto platforms, luring victims with false promises of exclusive investment opportunities while deploying sophisticated JavaScript-based drainer scripts. Upon interaction, these scripts surreptitiously drain connected wallets of tokens and NFTs without explicit consent, leveraging deceptive UI elements to obscure transaction details. Users who connect their wallets risk irreversible financial losses as funds are immediately siphoned to attacker-controlled addresses under the guise of 'processing fees' or 'verification steps'. This domain was flagged after analysis revealed critical red flags, including its recent registration through Gname.com Pte. Ltd. on May 02, 2026—an unusually short timeframe for a legitimate platform. The domain resolves to IP address 172.67.135.66 and uses a Let's Encrypt SSL certificate to appear legitimate, though this alone offers no guarantees of safety. Notably, VirusTotal reports zero detections (0/95 scanners) as of the latest query, indicating a novel or evasive threat that evades conventional detection methods. The absence of prior blocklist entries suggests this campaign may be in its early operational phase, targeting unsuspecting users who bypass basic security checks. If you've visited nextepochmarket.xyz or connected a wallet, immediately revoke any active permissions via your wallet provider's security settings and transfer remaining assets to a clean wallet. Do not interact further with the domain—even if prompted to 'reconnect' or 're-authenticate.' Report the domain to PhishDestroy for deactivation and share your findings with your wallet provider to aid in blocking the associated addresses. Exercise heightened caution with domains registered within the last 30 days, and always verify URLs against trusted sources before engagement. Enable multi-factor authentication on all crypto accounts and use hardware wallets for sensitive transactions to mitigate exposure to drainer scripts. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260504-845F1A TLS cert SHA-256: f8cac2606d2f7749afbe18169f130674b732cb739db6e666da58cce5f5abaaf1 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/nextepochmarket.xyz/ JSON API: https://api.destroy.tools/v1/check?domain=nextepochmarket.xyz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 145,625 domains (56,156 alive under monitoring, 89,209 confirmed takedowns/dead). Site: https://phishdestroy.io