# PhishDestroy threat dossier — prayerbox.xyz ================================================================ Fetched: 2026-07-30 12:01:47 UTC Canonical: https://phishdestroy.io/domain/prayerbox.xyz/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 6/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Chong Lua Dao, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar AlienVault OTX: 4 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 216.198.79.1 (US, Atlanta) ASN: AS16509 Amazon.com, Inc. Hosting org: Lefkoff Industries Registrar: Spaceship, Inc. Nameservers: ["ns1.vercel-dns.com", "ns2.vercel-dns.com"] Page title: Prayer Box Prayer Requests HTTP response: 307 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-09-07 Status: INVALID chain Fingerprint: cfe3ad802e296fddb3a1fcb481d86551ef013ae3a89b3bf98fea871f54ad1761 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-27 22:23:09 UTC (by PhishDestroy tracker) Last verified: 2026-07-30 12:33:11 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 22:24:50 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] prayerbox.xyz Safety Check — Vercel-Hosted Phishing Site Detected Analysis conducted on July 27, 2026, identifies prayerbox.xyz as an active phishing domain exhibiting high-risk characteristics. The domain is registered through Spaceship, Inc., a registrar frequently observed in recent phishing campaigns. Infrastructure analysis reveals the domain utilizes nameservers ns1.vercel-dns.com and ns2.vercel-dns.com, indicating hosting on Vercel's platform, which has been increasingly leveraged for transient phishing operations due to its ephemeral deployment capabilities. At the time of assessment, the domain returns an HTTP 307 Temporary Redirect status, a behavior commonly employed to obscure the final malicious destination or to evade automated detection systems. Detection metrics indicate limited but targeted awareness within the security community. The domain appears on one security blocklist, specifically PhishDestroy, suggesting preliminary identification of malicious intent. VirusTotal telemetry reports that 6 of 91 security vendors flag the domain as malicious, providing corroborating evidence of its phishing classification. The absence of broader detection does not imply benign status; rather, it reflects the domain's recent activation or limited exposure. The exact nature of the phishing content remains unconfirmed, as the page title and targeted brand are not specified in available intelligence. No evidence links the domain to a specific phishing kit or known threat actor infrastructure. Defenders are advised to treat prayerbox.xyz as an active threat. Network-level blocking is recommended, particularly for organizations utilizing Vercel-hosted services, due to the domain's nameserver association. Security teams should monitor for related domains registered through Spaceship, Inc., or resolving to Vercel's nameservers, as these may indicate a broader campaign. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: cfe3ad802e296fddb3a1fcb481d86551ef013ae3a89b3bf98fea871f54ad1761 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/prayerbox.xyz/ JSON API: https://api.destroy.tools/v1/check?domain=prayerbox.xyz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,633 domains (83,358 alive under monitoring, 110,015 confirmed takedowns/dead). Site: https://phishdestroy.io