# PhishDestroy threat dossier — pc.basisex.info ================================================================ Fetched: 2026-07-25 12:49:43 UTC Canonical: https://phishdestroy.io/domain/pc.basisex.info/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 95/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.96.3 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: CloudFlare, Inc. Registrar: GNAME.COM PTE. LTD. Nameservers: ["jermaine.ns.cloudflare.com", "romina.ns.cloudflare.com"] HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-10-12 Status: INVALID chain Fingerprint: b99dcbeaa42cf2754d859796e80d620a28681d1bf078d31ebf3bf3b5447e795b Subject Alternative Names (related infrastructure — often same operator): - basisex.info ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-23 15:41:36 UTC (by PhishDestroy tracker) Last verified: 2026-07-25 12:26:32 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f8f34-62df-74ed-b026-d838c6d2e01e/ Wayback Machine: https://web.archive.org/web/*/pc.basisex.info crt.sh CT logs: https://crt.sh/?q=%25.pc.basisex.info Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=pc.basisex.info AlienVault OTX: https://otx.alienvault.com/indicator/domain/pc.basisex.info URLhaus: https://urlhaus.abuse.ch/host/pc.basisex.info/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-23 15:43:56 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] pc.basisex.info Safety Check — Phishing Detected Analysis of pc.basisex.info indicates that the domain is currently active and associated with a generic phishing threat. The domain resolves to a single IPv4 address, 188.114.96.3, which is the only A‑record observed in DNS queries. No nameserver information is available (NS_NOT_FOUND), limiting insight into the registrar or hosting environment. VirusTotal records show the domain was submitted to 91 scanning engines, and none of those vendors raised a detection at the time of the scan; this absence of alerts does not constitute evidence of safety, especially given the domain’s presence on a security blocklist. The blocklist entry is corroborated by PhishDestroy, which has actively blocked the domain, confirming that at least one reputable anti‑phishing service flags it as malicious. No additional intelligence such as SSL certificate status, HTTP response codes, page title, or brand targeting is available, leaving the content and exact phishing vector unverified. Consequently, the primary certainty is the domain’s active resolution to 188.114.96.3, its inclusion on a known blocklist, and its detection by PhishDestroy. Uncertainties remain regarding the underlying hosting provider, registrar details, and the specific phishing payload or lure employed. Defensive recommendations include adding pc.basisex.info and its resolving IP address to network blocklists, enforcing URL filtering policies that deny access to the domain, and monitoring DNS logs for any future changes to nameserver or IP assignments. Continuous re‑scanning with multiple threat‑intel services is advised to capture any emerging malicious indicators that may appear as the campaign evolves. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: b99dcbeaa42cf2754d859796e80d620a28681d1bf078d31ebf3bf3b5447e795b ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/pc.basisex.info/ JSON API: https://api.destroy.tools/v1/check?domain=pc.basisex.info Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 190,631 domains (60,817 alive under monitoring, 128,255 confirmed takedowns/dead). Site: https://phishdestroy.io