# PhishDestroy threat dossier — playnance.fr ================================================================ Fetched: 2026-07-31 10:54:45 UTC Canonical: https://phishdestroy.io/domain/playnance.fr/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: genericcrypto ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 5/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, CRDF, Gridinsoft, Kaspersky, SOCRadar Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 104.21.4.115 (US, San Francisco) ASN: ASAS13335 CLOUDFLARENET - Cloudflare, Inc., US Hosting org: AS13335 Cloudflare, Inc. Registrar: Dynadot Inc Nameservers: dayana.ns.cloudflare.com, javier.ns.cloudflare.com Registered: 2026-03-25 Expires: 2027-03-25 Page title: Playnance | The Blockchain Infrastructure for Web3 On-Chain Entertainment HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE1 Expires: 2026-10-23 Status: INVALID chain Fingerprint: 641bab3894b4205f8465a9fba5990302e9b97063519118794de14f31232e62fa ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-03-25 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 16:35:14 UTC (by PhishDestroy tracker) First reported: 2026-07-27 14:53:24 UTC (abuse notice filed) Last verified: 2026-07-31 12:32:39 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa402-2e82-74be-9279-c1f715d99d56/ Wayback Machine: https://web.archive.org/web/*/playnance.fr crt.sh CT logs: https://crt.sh/?q=%25.playnance.fr Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=playnance.fr AlienVault OTX: https://otx.alienvault.com/indicator/domain/playnance.fr URLhaus: https://urlhaus.abuse.ch/host/playnance.fr/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 16:35:47 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] playnance.fr Phishing Campaign Detected playnance.fr is a newly registered domain (created 25 Mar 2026) that resolves to the Cloudflare‑owned address 172.67.132.8. The registration was performed through Dynadot Inc, and the authoritative name servers are dayana.ns.cloudflare.com and javier.ns.cloudflare.com. VirusTotal analysis shows that 1 of 91 security vendors currently flags the domain, indicating that at least one AV engine has identified malicious behavior. The domain is listed on a single public blocklist and is actively blocked by the PhishDestroy service, confirming that security‑focused feeds consider it a phishing threat. No additional public intelligence such as page title, SSL certificate details, or HTTP response codes is available at this time, so the exact content and lure technique remain uncertain. The presence of a Cloudflare front‑end suggests the operators may be leveraging the provider’s CDN and DDoS protection to hide the true origin of any malicious payload. Defenders should add playnance.fr to outbound filtering rules, enforce DNS‑level blocking, and monitor for any internal connections to the IP 172.67.132.8. Network logs should be inspected for repeated DNS queries or HTTP requests to this address, and any detected traffic should be quarantined. Because the domain is still active, continuous re‑evaluation is required; periodic rescans with VirusTotal and checks against additional blocklists are recommended to capture any new detections. Organizations using threat‑intel platforms should ingest the blocklist entry and correlate it with endpoint telemetry to identify compromised hosts that may have interacted with the site. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-6CB0D5 Favicon MD5: 9e2cd9b0b43e70e94770ae43933468dd TLS cert SHA-256: 641bab3894b4205f8465a9fba5990302e9b97063519118794de14f31232e62fa ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/playnance.fr/ JSON API: https://api.destroy.tools/v1/check?domain=playnance.fr Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 196,262 domains (84,108 alive under monitoring, 27,268 confirmed neutralized). Site: https://phishdestroy.io