# PhishDestroy threat dossier — play.twitbit.in ================================================================ Fetched: 2026-06-27 14:31:40 UTC Canonical: https://phishdestroy.io/domain/play.twitbit.in/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 99/100 (PhishDestroy scoring — see methodology below) Scam classification: Crypto Drainer ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/92 security vendors flagged this domain Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 91.204.209.3 (GB, Fareham) ASN: AS52148 Enix Ltd Hosting org: Enix Ltd Registrar: Endurance International Group India Private Limited Nameservers: ns1.xolohost.com, ns2.xolohost.com Registered: 2017-05-22 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R13 Expires: 2026-08-09 Status: INVALID chain Fingerprint: 73c2db3b4e2a0d14aba82ae1da13004e8d38e77d85aeeff27d8fc0814c5c3507 Subject Alternative Names (related infrastructure — often same operator): - www.play.twitbit.in ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2017-05-22 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-15 20:11:58 UTC (by PhishDestroy tracker) First reported: 2026-05-15 17:17:26 UTC (abuse notice filed) Last verified: 2026-06-27 16:20:35 UTC Neutralised: 2026-06-06 17:30:45 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e2c9d-ab6f-75ae-b765-92f561dc63ab/ URLQuery: https://urlquery.net/report/314b14dc-cd27-4529-8b1c-0d2cc6bc3c34 Wayback Machine: https://web.archive.org/web/*/play.twitbit.in crt.sh CT logs: https://crt.sh/?q=%25.play.twitbit.in Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=play.twitbit.in AlienVault OTX: https://otx.alienvault.com/indicator/domain/play.twitbit.in URLhaus: https://urlhaus.abuse.ch/host/play.twitbit.in/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-15 20:12:34 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] The domain play.twitbit.in has been flagged as a crypto drainer that mimics legitimate login portals. When users enter credentials or connect wallets, it silently siphons cryptocurrency to attacker-controlled addresses. Given its active status and low detection rate, this site poses a clear danger to visitors seeking unauthorized streaming services or login access. PhishDestroy identifies that this domain went live on May 22, 2017, and currently shows 0 detections out of 95 antivirus engines on VirusTotal. It is registered through Endurance International Group India Private Limited and secured with a Let’s Encrypt SSL certificate. The site resolves to IP address 91.204.209.3, which may be linked to previous malicious campaigns. These technical indicators suggest that the infrastructure is intentionally designed to fly under the radar while targeting unsuspecting users. If you visited play.twitbit.in, immediately disconnect any connected wallets and revoke permissions using your wallet’s security settings. Do not enter any credentials or approve transactions. Scan your device with updated antivirus and consider rotating passwords used on other platforms. Report the domain and any suspicious transactions to PhishDestroy for further investigation and prevention of future attacks. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260515-3492A4 Favicon MD5: fd8c5f40726d24d63bab6a9a48ee3f0d TLS cert SHA-256: 73c2db3b4e2a0d14aba82ae1da13004e8d38e77d85aeeff27d8fc0814c5c3507 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/play.twitbit.in/ JSON API: https://api.destroy.tools/v1/check?domain=play.twitbit.in Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 170,870 domains (12,734 alive under monitoring, 157,726 confirmed takedowns/dead). Site: https://phishdestroy.io