# PhishDestroy threat dossier — nt0os.xyz ================================================================ Fetched: 2026-07-28 14:19:01 UTC Canonical: https://phishdestroy.io/domain/nt0os.xyz/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 8/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, BitDefender, CyRadar, ESET, Forcepoint ThreatSeeker, G-Data, SOCRadar, Sophos AlienVault OTX: 4 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 103.224.182.249 (US, San Diego) ASN: AS133618 Trellian Pty. Limited Hosting org: Trellian Pty. Limited Registrar: Dynadot Inc Nameservers: ["5014.ns1.abovedomains.com", "5014.ns2.abovedomains.com"] HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-09-20 Status: INVALID chain Fingerprint: 29dbe75c2ce06721a8e85f91e6ea4f279e5b67b934d1ba374e24937433cab5f2 Subject Alternative Names (related infrastructure — often same operator): - 20547.loan - 336600.co - 41924.one - 4562m.xyz - 45800.one - 5555777.vip - 57120.loan - 666weixiao.xyz - 75546.one - autopayment.co - aviatorsglasses.shop - droventa.cfd - egbf32b.top - finnick302.sbs - hh40196.cc ... +28 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-27 14:43:09 UTC (by PhishDestroy tracker) Last verified: 2026-07-28 12:54:44 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 14:46:29 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] nt0os.xyz Generic Phishing Site Alert Analysis conducted on July 27, 2026, identifies nt0os.xyz as an active phishing domain with high-risk indicators. The domain is registered through Dynadot Inc and currently resolves to the IP address 103.224.182.249, associated with nameservers 5014.ns1.abovedomains.com and 5014.ns2.abovedomains.com. At the time of assessment, the domain returns an HTTP 200 status, suggesting an operational web page, though the exact content and target of the phishing attempt remain unconfirmed due to lack of page-level analysis. Security vendor detections on VirusTotal indicate that 8 out of 91 engines flag this domain as malicious, reinforcing its classification as a phishing threat. The domain appears on one security blocklist, specifically PhishDestroy, further corroborating its malicious status. No additional details regarding the specific brand impersonated, phishing kit used, or scam category (e.g., credential harvesting, financial fraud) are available in the current intelligence. Infrastructure analysis reveals no anomalies in the registration or hosting setup beyond standard bulk-domain patterns. The domain's nameservers are consistent with those used by above-domains.com, a provider frequently observed in low-cost domain registrations that may lack stringent abuse controls. The IP address 103.224.182.249 has been previously linked to other suspicious domains, though no direct attribution to a known threat actor or campaign is present in the available data. Defenders are advised to treat nt0os.xyz as an active phishing threat. Network-level blocking of the domain and its resolving IP is recommended, alongside monitoring for connections to 103.224.182.249 or the associated nameservers. Organizations should also review logs for any user interactions with this domain, particularly in regions where the hosting IP is geolocated. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: 29dbe75c2ce06721a8e85f91e6ea4f279e5b67b934d1ba374e24937433cab5f2 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/nt0os.xyz/ JSON API: https://api.destroy.tools/v1/check?domain=nt0os.xyz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 211,155 domains (85,595 alive under monitoring, 124,530 confirmed takedowns/dead). Site: https://phishdestroy.io