# PhishDestroy threat dossier — p81u.xyz ================================================================ Fetched: 2026-07-29 22:24:44 UTC Canonical: https://phishdestroy.io/domain/p81u.xyz/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 16/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Google Safe Browsing, Gridinsoft, Lionic, SOCRadar, Sophos, VIPRE, Webroot AlienVault OTX: 4 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist Google Safe Browsing: FLAGGED ## INFRASTRUCTURE ---------------------------------------------------------------- Registrar: Gname.com Pte. Ltd. Nameservers: ["ns1.1111343.com", "ns2.1111343.com", "ns3.1111343.com", "ns4.1111343.com"] ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-27 18:13:08 UTC (by PhishDestroy tracker) Last verified: 2026-07-29 21:08:32 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 18:15:24 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is p81u.xyz a generic phishing site? Analysis of p81u.xyz as of 27 July 2026 indicates the domain is actively serving content (HTTP 200) and is associated with a generic phishing campaign. The domain resolves to four authoritative name servers (ns1‑ns4.1111343.com) and is registered through Gname.com Pte. Ltd. Google Safe Browsing has flagged the site for social engineering, and VirusTotal records show that 16 of 91 scanned security vendors have raised detections against the domain. It appears on one external blocklist and is currently blocked by the PhishDestroy feed. The risk rating assigned is high and the threat type is classified as generic phishing. The infrastructure details beyond the name server list are not publicly disclosed, and no additional indicators such as IP address, SSL certificate, or page title have been released. Consequently, defenders should treat any traffic to p81u.xyz as malicious. Recommended actions include adding the domain to local deny lists, updating firewall and proxy rules to block HTTP and HTTPS connections, and ensuring that endpoint protection solutions incorporate the latest threat intelligence feeds that contain this indicator. Continuous monitoring for changes in the domain’s registration, name‑server configuration, or detection scores is advised, as alterations could signal a shift in the underlying campaign. Organizations that employ web‑filtering solutions should verify that the domain is included in their blocklists, and incident response teams should be prepared to investigate any user‑initiated connections or credential submissions that may have been directed to this site. ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/p81u.xyz/ JSON API: https://api.destroy.tools/v1/check?domain=p81u.xyz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,509 domains (82,972 alive under monitoring, 110,024 confirmed takedowns/dead). Site: https://phishdestroy.io