# PhishDestroy threat dossier — partner.katies.xyz ================================================================ Fetched: 2026-04-22 04:53:23 UTC Canonical: https://phishdestroy.io/domain/partner.katies.xyz/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users (type: status_split) (score: 1/6) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/94 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Forcepoint ThreatSeeker ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 216.198.79.65 (US, Cleveland) ASN: AS16509 Amazon.com, Inc. Hosting org: CYPRESS COMMUNICATIONS, LLC Registrar: Unstoppable Domains, Inc. Nameservers: ["naya.ns.cloudflare.com", "patryk.ns.cloudflare.com"] Registered: 2026-04-18 Page title: nioctiB - Viction Staking HTTP response: 530 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-06-25 Status: INVALID chain Fingerprint: 5c48b47362f8f46618943251b1930d0914f4e86c2c0ef6584cf5698f06e78563 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-18 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-18 22:03:35 UTC (by PhishDestroy tracker) Earliest abuse rec: 2026-04-18 19:05:25 UTC — PREDATES current WHOIS registration; retained from a previous registration cycle of the same domain name Last verified: 2026-04-22 07:24:12 UTC Neutralised: 2026-04-21 22:02:13 UTC Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners Note: one or more events above predate the WHOIS creation date. This typically means the same domain name was previously registered, detected, dropped, and then re-registered by a new party. PhishDestroy preserves the full historical record for operator-attribution research even when the underlying infrastructure changes hands. ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019da1f8-342c-76ee-95d7-32ce8809c2c0/ URLQuery: https://urlquery.net/report/be112fee-6c3a-4844-a68d-ff6be8a47f9d Wayback Machine: https://web.archive.org/web/*/partner.katies.xyz crt.sh CT logs: https://crt.sh/?q=%25.partner.katies.xyz Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=partner.katies.xyz AlienVault OTX: https://otx.alienvault.com/indicator/domain/partner.katies.xyz URLhaus: https://urlhaus.abuse.ch/host/partner.katies.xyz/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-18 22:04:14 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies partner.katies.xyz as a active crypto drainer domain mimicking Viction Staking services to steal cryptocurrency assets from unwary users. The site employs a misleading page title, 'nioctiB - Viction Staking', to deceive visitors into connecting their wallets or transferring funds under false pretenses. Security assessments confirm its malicious intent, warranting immediate caution and avoidance. This domain was flagged by 1 of 95 VirusTotal vendors, raising immediate risk concerns for visitors. It resolves to IP address 216.198.79.65, registered through Unstoppable Domains Inc. on November 07, 2025. Despite using a Let's Encrypt SSL certificate to appear legitimate, its recent creation date and minimal detection rate indicate a likely new threat actor tool designed to evade early detection systems. PhishDestroy advises blocking partner.katies.xyz at the network level and discontinuing all interactions with the site due to active malicious behavior. Users who accessed this domain should scan their devices for wallet-draining malware and revoke any connected permissions. Implement DNS filtering rules to prevent future access. Report this domain immediately to threat intelligence platforms to aid in takedown efforts. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260418-DE9695 Favicon MD5: 300f18e28d55d87ab9d70745a4d2b14c TLS cert SHA-256: 5c48b47362f8f46618943251b1930d0914f4e86c2c0ef6584cf5698f06e78563 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/partner.katies.xyz/ JSON API: https://api.destroy.tools/v1/check?domain=partner.katies.xyz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io