# phantomalert.xyz — MALICIOUS > Phantomalert.xyz is a high-risk phishing domain now offline. Stay vigilant and protect your organization from similar threats. ## Summary PhishDestroy identifies phantomalert.xyz as a high-risk generic phishing domain. Its intent was to deceive users into divulging sensitive information. Technical indicators include its registration via a dead domain service and listings on four separate security blocklists. VirusTotal flagged it by 12 out of 95 security vendors, reinforcing its malicious nature. Currently, phantomalert.xyz is offline, mitigating immediate risk. PhishDestroy recommends continued monitoring for related threats and updating blocklists to prevent future incidents. ## Threat Details - Verdict: MALICIOUS - Site status: alive (HTTP 530) - Target brand: Phantom - Page title: Unlock Finance Success with AMLTestWallet & AMLCheck 2! ## Domain Intelligence - Registered: 2026-02-21 07:01:08 - IP: 104.21.23.140 - SSL Issuer: WE1 ## Detection Status - VirusTotal: 12 vendors flagged Vendors: ["ChainPatrol", "alphaMountain.ai", "CRDF", "CyRadar", "Forcepoint ThreatSeeker", "Fortinet", "Gridinsoft", "Lionic", "Seclookup", "SOCRadar", "Sophos", "Webroot"] - Google Safe Browsing: clean - Blocklists: 3 hits Lists: ["PhishDestroy", "MetaMask", "ScamSniffer"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019b7fb9-1aa3-725b-89c9-f6aa95000e0c.png - PhishDestroy: https://phishdestroy.io/domain/phantomalert.xyz/ - LLM endpoint: https://phishdestroy.io/domain/phantomalert.xyz/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/phantomalert.xyz/ Last updated: 2026-03-19