# PhishDestroy threat dossier — puresilver.xyz ================================================================ Fetched: 2026-07-28 17:19:47 UTC Canonical: https://phishdestroy.io/domain/puresilver.xyz/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/91 security vendors flagged this domain Flagging vendors: CRDF, Forcepoint ThreatSeeker AlienVault OTX: 4 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 103.224.182.245 (US, San Diego) ASN: AS133618 Trellian Pty. Limited Hosting org: Trellian Pty. Limited Registrar: OwnRegistrar, Inc. Nameservers: ["ns1.managedns1.com", "ns2.managedns1.com"] Page title: puresilver.xyz ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-27 21:43:09 UTC (by PhishDestroy tracker) Last verified: 2026-07-28 18:22:58 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 21:44:30 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] puresilver.xyz — Generic Phishing Report This investigation confirms that the domain puresilver.xyz remains active and returns an HTTP 200 status code for requests to its web server. Registration data shows the domain was created through OwnRegistrar, Inc., and its DNS zone is delegated to the authoritative name servers ns1.managedns1.com and ns2.managedns1.com. The host is listed on a single external security blocklist and is explicitly blocked by the PhishDestroy feed, indicating that at least one dedicated anti‑phishing platform has flagged the domain as malicious. VirusTotal scans reveal that two of ninety‑one scanning engines have generated detections, providing additional independent confirmation of suspicious activity. No public information about the page title, SSL certificate details, hosting IP address, or underlying infrastructure has been released, leaving the full technical composition of the phishing payload and its delivery mechanisms uncertain. The limited detection surface suggests a possibly short‑lived or low‑profile campaign that may rely on targeted distribution rather than broad‑scale spam. Defenders should immediately add puresilver.xyz to web‑proxy, DNS filtering, and endpoint allow‑list denial rules to prevent user navigation. Email security gateways must treat any message containing links to this domain as malicious and quarantine or reject such traffic. Continuous re‑scanning with multi‑engine services such as VirusTotal is recommended to capture any new detections that may emerge as the site evolves. Incident response teams should capture HTTP request logs, TLS handshake metadata (if HTTPS is later enabled), and any content retrieved from the site for forensic analysis. Because the hosting infrastructure and IP address have not been disclosed, threat‑intel analysts should query passive DNS, historical WHOIS records, and reverse‑lookup services to identify any additional domains that share the same name servers or registrar, as these may represent an expanded infrastructure. ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/puresilver.xyz/ JSON API: https://api.destroy.tools/v1/check?domain=puresilver.xyz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 212,243 domains (86,683 alive under monitoring, 124,530 confirmed takedowns/dead). Site: https://phishdestroy.io