# PhishDestroy threat dossier — primeminers.io ================================================================ Fetched: 2026-07-27 09:46:59 UTC Canonical: https://phishdestroy.io/domain/primeminers.io/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 63/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 7/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, BitDefender, Forcepoint ThreatSeeker, G-Data, Gridinsoft, Netcraft, SOCRadar AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 198.54.120.225 (US, Chicago) ASN: AS22612 Namecheap, Inc. Hosting org: Namecheap, Inc. Registrar: NAMECHEAP INC Nameservers: dns1.namecheaphosting.com, dns2.namecheaphosting.com Registered: 2022-05-02 Expires: 2027-05-02 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Sectigo Limited / Sectigo Public Server Authentication CA DV R36 Expires: 2027-01-05 Status: INVALID chain Fingerprint: 0f25ffed90c3e168579cd241e1a4185978d517ea441bb91e5b3ae5b1c9b0e903 Subject Alternative Names (related infrastructure — often same operator): - www.primeminers.io ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2022-05-02 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 07:56:27 UTC (by PhishDestroy tracker) Last verified: 2026-07-27 09:03:01 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa23e-99b3-777c-9387-b51330984672/ Wayback Machine: https://web.archive.org/web/*/primeminers.io crt.sh CT logs: https://crt.sh/?q=%25.primeminers.io Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=primeminers.io AlienVault OTX: https://otx.alienvault.com/indicator/domain/primeminers.io URLhaus: https://urlhaus.abuse.ch/host/primeminers.io/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 07:56:41 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] primeminers.io: Confirmed Phishing Site Analysis of primeminers.io indicates that the domain is actively used for phishing. VirusTotal records show 7 of 91 scanned security vendors flag the domain as malicious, suggesting a consensus among multiple engines of suspicious behavior. The domain is listed on at least one public security blocklist and is explicitly blocked by the PhishDestroy service, confirming that it has been observed delivering fraudulent content. DNS resolution points to the IPv4 address 198.54.120.225; the host does not appear to be a known cloud provider and is likely a dedicated server used by the operators. Registration data reveal that the domain was created on 2 May 2022 through Namecheap Inc., and the authoritative name servers are dns1.namecheaphosting.com and dns2.namecheaphosting.com, both typical of Namecheap‑hosted domains. No evidence of SSL/TLS certificates, HTTP response codes, or page titles has been published, so the current surface of the site remains uncharacterized. The persistence of the domain for more than four years, combined with multiple vendor detections and blocklist listings, raises its risk rating to high. Defenders should add 198.54.120.225 and primeminers.io to network‑level deny lists, enforce URL filtering in web proxies, and monitor DNS queries for the domain. Incident response teams should treat any credential or payment information submitted to this domain as compromised and advise affected users to reset credentials. Continuous re‑inspection of the site for changes in hosting, SSL adoption, or new phishing pages is recommended. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 7fb976005c485624d64a4d0209d01a46 TLS cert SHA-256: 0f25ffed90c3e168579cd241e1a4185978d517ea441bb91e5b3ae5b1c9b0e903 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/primeminers.io/ JSON API: https://api.destroy.tools/v1/check?domain=primeminers.io Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 204,403 domains (79,827 alive under monitoring, 123,545 confirmed takedowns/dead). Site: https://phishdestroy.io