# PhishDestroy threat dossier — pro.smarterbu.top ================================================================ Fetched: 2026-07-30 00:53:49 UTC Canonical: https://phishdestroy.io/domain/pro.smarterbu.top/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 82/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain Flagging vendors: CRDF Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.237.129.236 (US, Chicago) ASN: AS63949 Akamai Connected Cloud Hosting org: Akamai Technologies, Inc. Registrar: NameSilo,LLC !!! REGISTRAR INTEGRITY ALERT — NameSilo !!! NameSilo is a registrar documented by PhishDestroy as (1) publicly lying about received abuse reports, (2) shielding a $20M+ Monero-theft operation (xmrwallet.com) for 10 continuous years, and (3) retaliating against PhishDestroy by getting our X/Twitter account @Phish_Destroy banned after we published the evidence. Researchers/victims must ALWAYS CC compliance@icann.org on every abuse ticket — NameSilo has a track record of later claiming reports were never received. Primary sources: https://phishdestroy.io/namesilo-killed-our-twitter https://phishdestroy.io/xmrwallet-namesilo-exposed Nameservers: ["ns1.ns306.parklogic.com.", "ns2.ns306.parklogic.com."] Page title: Redirecting... HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE1 Expires: 2026-10-17 Status: INVALID chain Fingerprint: 596137c93ebd6efa965726bea814dcbb626a92fa20c17c23838a4ac5d995c903 Subject Alternative Names (related infrastructure — often same operator): - smarterbu.top ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-27 22:03:10 UTC (by PhishDestroy tracker) Last verified: 2026-07-30 01:49:57 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 22:04:20 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is pro.smarterbu.top a Scam? This domain pro.smarterbu.top is currently classified as a generic phishing site with a high risk rating. The web server returns HTTP status code 200, indicating that the site is actively serving content. VirusTotal analysis shows that one out of ninety‑one scanned security vendors flagged the domain, confirming at least a minimal detection across the ecosystem. The domain is registered through NameSilo, LLC and utilizes the Parklogic hosting provider’s nameservers ns1.ns306.parklogic.com and ns2.ns306.parklogic.com. It appears on a single external security blocklist and is already blocked by the PhishDestroy sink‑hole, which suggests that at least one defensive network has taken active mitigation steps. No additional infrastructure details such as IP address, ASN, or geographic location are disclosed in the available intelligence, leaving the broader hosting context uncertain. Defenders should ensure that their perimeter controls explicitly deny or sandbox any traffic to pro.smarterbu.top, add the domain to internal phishing blocklists, and monitor DNS queries for the associated Parklogic nameservers for potential future campaigns. Continuous re‑evaluation is recommended, as the single vendor detection may increase if more security products observe malicious activity. Given the active status and the presence on a blocklist, the domain should be treated as hostile and removed from any allow lists. Organizations employing web filtering should also consider updating any URL reputation services with this indicator to reduce exposure to downstream phishing attempts. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: 596137c93ebd6efa965726bea814dcbb626a92fa20c17c23838a4ac5d995c903 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/pro.smarterbu.top/ JSON API: https://api.destroy.tools/v1/check?domain=pro.smarterbu.top Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,512 domains (93,337 alive under monitoring, 99,913 confirmed takedowns/dead). Site: https://phishdestroy.io