# osb18.cc — SUSPICIOUS > PhishDestroy identifies osb18.cc as a crypto drainer posing as a legit service. 2/95 VirusTotal vendors flagged it since creation on March 15, 2022. ## Summary PhishDestroy confirms osb18.cc operates as a crypto drainer, a specialized phishing threat designed to steal cryptocurrency funds by tricking users into connecting their wallets or entering seed phrases. The domain mimics legitimate crypto services to harvest private keys or initiate unauthorized transfers. Evidence shows this site was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on March 15, 2022, and currently resolves to the IP address 172.67.151.120. Security scans by VirusTotal reveal only 2 out of 95 vendors flagged the domain, highlighting how stealthy and targeted this threat is for cryptocurrency users. The site’s SSL certificate is issued by Google Trust Services, which may give a false sense of legitimacy to visitors. Despite this, the domain’s short operational history and low detection rate underscore the elevated risk it poses to unsuspecting users, particularly those in the crypto community. Brand impersonation is a key tactic here, as attackers often leverage trust in recognizable names to lure victims into connecting their wallets or submitting sensitive information. If you visited osb18.cc, disconnect your wallet immediately and revoke any permissions granted to unknown sites. Use blockchain explorers to check for unauthorized transactions and consider transferring remaining assets to a new wallet with a different seed phrase. Enable multi-factor authentication on all crypto accounts and report this domain to your antivirus provider or PhishDestroy for further analysis. Always verify URLs and avoid clicking links from unsolicited messages. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2022-03-15 20:20:19 - Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED - IP: 172.67.151.120 ## Detection Status - VirusTotal: 2 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/b1ff2eb6-7ef4-43cb-9cac-6799ab6546db - PhishDestroy: https://phishdestroy.io/domain/osb18.cc/ - LLM endpoint: https://phishdestroy.io/domain/osb18.cc/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/osb18.cc/ Last updated: 2026-03-26