# PhishDestroy threat dossier — purevietnamlemon.online ================================================================ Fetched: 2026-05-17 15:31:34 UTC Canonical: https://phishdestroy.io/domain/purevietnamlemon.online/ ## VERDICT ---------------------------------------------------------------- SUSPICIOUS — under active investigation Composite threat score: 36/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/95 security vendors flagged this domain Flagging vendors: desenmascara.me ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 163.61.188.5 (US, Staten Island) ASN: AS153568 NEW DHAKA HARDWARE Hosting org: MIT Registrar: Global Domain Group LLC Nameservers: dns1.lytehosting.com, dns2.lytehosting.com, dns3.lytehosting.com, dns4.lytehosting.com Registered: 2025-05-10 Page title: purevietnamlemon.online - Tien Giang Province,, Vietnam HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R13 Expires: 2026-08-13 Status: INVALID chain Fingerprint: f5297798b6fc00c159f71bb8c439556841fcf0b18eb3fde8f37a1ca2e2ff3a1d Subject Alternative Names (related infrastructure — often same operator): - mail.purevietnamlemon.online - www.purevietnamlemon.online ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-05-10 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-17 15:48:10 UTC (by PhishDestroy tracker) First reported: 2026-05-17 12:49:58 UTC (abuse notice filed) Last verified: 2026-05-17 18:15:07 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e35fa-049d-7079-bd29-a2dc7569be94/ URLQuery: https://urlquery.net/report/096a6a4d-9f17-451e-9248-2f5428eda50f Wayback Machine: https://web.archive.org/web/*/purevietnamlemon.online crt.sh CT logs: https://crt.sh/?q=%25.purevietnamlemon.online Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=purevietnamlemon.online AlienVault OTX: https://otx.alienvault.com/indicator/domain/purevietnamlemon.online URLhaus: https://urlhaus.abuse.ch/host/purevietnamlemon.online/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-17 15:48:56 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies purevietnamlemon.online as an active credential harvesting scam deployed by threat actors impersonating a Vietnamese business to trick users into submitting sensitive login credentials. This domain mimics legitimate service providers to harvest usernames, passwords, and financial details under the guise of product orders or membership sign-ups. Compromised accounts can be leveraged for follow-on fraud, including financial theft and identity takeover. Security teams and end users should treat any interaction with this domain as hostile and immediately cease all communication with the site. This domain was flagged by PhishDestroy with elevated risk due to confirmed evidence of malicious intent. It resolves to IP address 163.61.188.5 and was registered through Global Domain Group LLC on May 10, 2025. VirusTotal shows only 1 out of 95 security vendors currently detect this domain as malicious, highlighting the challenge of early detection in emerging phishing campaigns. The domain uses a valid Let's Encrypt SSL certificate to appear legitimate and increase user trust. The low detection rate is concerning as it allows the threat actor to operate undetected by most automated systems for extended periods, increasing the likelihood of successful compromise. If you have visited purevietnamlemon.online, immediately cease any interaction and check your browser history for any data submitted to the site. Do not reuse passwords across services—change any credentials that may have been entered on this domain. Enable multi-factor authentication on all critical accounts as an additional layer of protection. Report this domain to your security team or through PhishDestroy’s reporting system to help block future access. Monitor financial accounts and credit reports for unauthorized activity. Consider running a malware scan on devices used to access this site, as credential phishing campaigns often lead to secondary infections. Stay vigilant for follow-on phishing attempts that may use this domain’s compromise to target you or your organization directly. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260517-B16B12 TLS cert SHA-256: f5297798b6fc00c159f71bb8c439556841fcf0b18eb3fde8f37a1ca2e2ff3a1d ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/purevietnamlemon.online/ JSON API: https://api.destroy.tools/v1/check?domain=purevietnamlemon.online Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 150,665 domains (30,588 alive under monitoring, 119,786 confirmed takedowns/dead). Site: https://phishdestroy.io