# PhishDestroy threat dossier — pywxexecgcx.com ================================================================ Fetched: 2026-07-28 20:24:22 UTC Canonical: https://phishdestroy.io/domain/pywxexecgcx.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 13/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Kaspersky, Lionic, SOCRadar, Sophos, VIPRE AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 112.213.108.93 (HK, Fo Tan) ASN: AS152194 CTG Server Limited Hosting org: Mega-ii IDC Registrar: Dominet (HK) Limited Nameservers: ["ns7.alidns.com", "ns8.alidns.com"] Page title: GCEX HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-08-29 Status: INVALID chain Fingerprint: defa6cada860a7e475cd572d4e3b13e67c8c6392649f64d9df44d46e01a21a5d Subject Alternative Names (related infrastructure — often same operator): - gcexexxs.com - gcexrtaatw.top - gcexx.com - gcxchoog.com - ggxcexgx.com - gxecghz.com - gxxecgcex.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-27 22:23:08 UTC (by PhishDestroy tracker) Last verified: 2026-07-28 21:04:09 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 22:25:02 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] pywxexecgcx.com: Confirmed Phishing Site Analysis of the domain pywxexecgcx.com, observed on July 27, 2026, indicates active phishing infrastructure. The domain resolves to the authoritative name servers ns7.alidns.com and ns8.alidns.com, both of which are typical of Alibaba‑owned DNS services. An HTTP request to the root URL returns a 200 OK status, confirming that a web server is actively responding. VirusTotal reports that 13 of 91 security vendors have flagged the domain as malicious, providing independent corroboration of its threat nature. The domain is listed on a single external security blocklist and is explicitly blocked by the PhishDestroy protection service, reinforcing the consensus that it should be considered hostile. Registration details show the domain was created through Dominet (HK) Limited, a registrar based in Hong Kong, but no further attribution such as ASN, IP geolocation, or SSL certificate information is available in the current data set. The specific content hosted on the site, including page title or brand targeting, has not been disclosed, leaving the exact phishing vector uncertain. Nevertheless, the combination of active HTTP response, multiple vendor detections, blocklist presence, and registrar information provides sufficient evidence for defensive operators to treat pywxexecgcx.com as a high‑risk phishing host. Recommended actions include adding the domain to network block lists, configuring web filters to deny traffic, monitoring DNS queries for related alidns.com name servers, and continuing to observe VirusTotal and other threat feeds for any changes in detection counts or additional intelligence. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 89d8e39eda078521f04fdde4aaf1aaac TLS cert SHA-256: defa6cada860a7e475cd572d4e3b13e67c8c6392649f64d9df44d46e01a21a5d ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/pywxexecgcx.com/ JSON API: https://api.destroy.tools/v1/check?domain=pywxexecgcx.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 208,133 domains (82,976 alive under monitoring, 124,125 confirmed takedowns/dead). Site: https://phishdestroy.io