# PhishDestroy threat dossier — ny.fnv.one ================================================================ Fetched: 2026-05-13 12:52:31 UTC Canonical: https://phishdestroy.io/domain/ny.fnv.one/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 95/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 14/95 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Lionic, Sophos, VIPRE, Webroot ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.67.168.62 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: NameSilo, LLC !!! REGISTRAR INTEGRITY ALERT — NameSilo !!! NameSilo is a registrar documented by PhishDestroy as (1) publicly lying about received abuse reports, (2) shielding a $20M+ Monero-theft operation (xmrwallet.com) for 10 continuous years, and (3) retaliating against PhishDestroy by getting our X/Twitter account @Phish_Destroy banned after we published the evidence. Researchers/victims must ALWAYS CC compliance@icann.org on every abuse ticket — NameSilo has a track record of later claiming reports were never received. Primary sources: https://phishdestroy.io/namesilo-killed-our-twitter https://phishdestroy.io/xmrwallet-namesilo-exposed Nameservers: junade.ns.cloudflare.com, olga.ns.cloudflare.com Registered: 2026-02-27 Page title: Fortnite Inventory Checker | Epic Games HTTP response: 530 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: none Status: INVALID chain ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-02-27 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-12 18:52:01 UTC (by PhishDestroy tracker) Last verified: 2026-05-13 15:12:21 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e1ce0-a1bd-74aa-95aa-b2854bd95af3/ Wayback Machine: https://web.archive.org/web/*/ny.fnv.one crt.sh CT logs: https://crt.sh/?q=%25.ny.fnv.one Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=ny.fnv.one AlienVault OTX: https://otx.alienvault.com/indicator/domain/ny.fnv.one URLhaus: https://urlhaus.abuse.ch/host/ny.fnv.one/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-12 18:53:27 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies ny.fnv.one as a credential harvesting phishing site designed to trick users into submitting sensitive login credentials under false pretenses. The domain mimics legitimate services, luring victims to enter personal or financial data on fraudulent login pages. This tactic is commonly used to steal account credentials, banking details, or other confidential information for identity theft or financial fraud. Given its observed behavior, users should avoid interacting with this domain entirely and treat any communication referencing ny.fnv.one as highly suspicious. This domain was flagged by 14 out of 95 VirusTotal security vendors, indicating a strong consensus among threat intelligence platforms about its malicious nature. The domain was registered through NameSilo, LLC on February 27, 2026, which is a recent creation and typically raises red flags for potential fraudulent activity. Additionally, it resolves to IP address 172.67.168.62 and holds a Let's Encrypt SSL certificate, which attackers often exploit to appear legitimate. The combination of a short domain age, low trust across security vendors, and active credential harvesting behavior places ny.fnv.one at an elevated risk level. If you visited ny.fnv.one or entered any information, immediately change the passwords for any accounts you may have exposed and enable multi-factor authentication where possible. Run a full antivirus scan on your device to check for malware or unauthorized access. Consider reporting the domain to your email provider or browser for blocking. Avoid future interactions with this domain and warn others who may have been targeted. For further safety guidance, refer to PhishDestroy's full report on this domain using unique seed 695d67. ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/ny.fnv.one/ JSON API: https://api.destroy.tools/v1/check?domain=ny.fnv.one Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 148,871 domains (40,678 alive under monitoring, 107,877 confirmed takedowns/dead). Site: https://phishdestroy.io