# PhishDestroy threat dossier — rain-buy-and-sell-bitcoin.apk.cafe ================================================================ Fetched: 2026-07-24 11:16:58 UTC Canonical: https://phishdestroy.io/domain/rain-buy-and-sell-bitcoin.apk.cafe/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Bitcoin ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain Flagging vendors: ChainPatrol Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 193.42.111.101 (NL, Amsterdam) ASN: ASAS60144 THREE-W-INFRA-AS 3W Infra B.V., NL Hosting org: AS60144 3W Infra B.V. Registrar: Devexpanse Ltd d/b/a Regery.com Nameservers: ["ns.anycastns1.org", "ns.anycastns2.org"] Page title: Android cafe download free Apks files HTTP response: 302 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE2 Expires: 2026-10-18 Status: INVALID chain Fingerprint: 4a5a745c2d6346950939a09aae23e1a8678a4b6fdffab72cae99161a8fa37ef8 Subject Alternative Names (related infrastructure — often same operator): - apk.cafe ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-21 15:10:30 UTC (by PhishDestroy tracker) First reported: 2026-07-21 13:16:01 UTC (abuse notice filed) Last verified: 2026-07-24 12:24:40 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f84ca-c463-74af-8f92-cb351ac18e9c/ URLQuery: https://urlquery.net/report/107e81e5-c68f-46cd-b394-0a8c72cd69f6 Wayback Machine: https://web.archive.org/web/*/rain-buy-and-sell-bitcoin.apk.cafe crt.sh CT logs: https://crt.sh/?q=%25.rain-buy-and-sell-bitcoin.apk.cafe Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=rain-buy-and-sell-bitcoin.apk.cafe AlienVault OTX: https://otx.alienvault.com/indicator/domain/rain-buy-and-sell-bitcoin.apk.cafe URLhaus: https://urlhaus.abuse.ch/host/rain-buy-and-sell-bitcoin.apk.cafe/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-21 15:10:46 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] rain-buy-and-sell-bitcoin.apk.cafe — Phishing Investigation rain-buy-and-sell-bitcoin.apk.cafe was observed resolving to the IPv4 address 193.42.111.101. The domain is listed on a single security blocklist and is actively blocked by the PhishDestroy filtering service. A VirusTotal analysis performed on the domain involved 95 independent scanning engines; at the time of the scan none reported a detection. The lack of detections does not constitute evidence of benign behavior, but it indicates that no known signatures have yet identified malicious payloads associated with the domain. The domain’s authoritative name server information could not be retrieved (NS_NOT_FOUND), limiting visibility into registration details and potential ownership. No additional intelligence such as Safe Browsing verdicts, Open Threat Exchange reports, registrar data, SSL certificate information, HTTP response codes, or trust‑score metrics is currently available. Consequently, the operational status of the site remains active, and the specific content served by the web server has not been captured. The classification as a generic phishing campaign is based on the naming pattern and the presence on a phishing‑focused blocklist. Because the domain's registration data is unavailable, attribution to a specific actor cannot be established. The absence of SSL/TLS details means that any transport‑layer encryption cannot be assessed, and the HTTP status code returned by the server is unknown. Defenders should continue to monitor DNS resolutions to 193.42.111.101, enforce existing PhishDestroy blocks, and consider adding the domain to local deny lists. Additional analysis, including HTTP content retrieval and TLS inspection, is recommended to confirm the presence of credential‑harvesting pages or other malicious functionality. Threat intelligence consumers should treat the domain as suspicious pending further investigation and incorporate it into automated phishing detection rules where feasible. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260721-469473 Favicon MD5: 85c8075388f32387761f404bc5798ecd TLS cert SHA-256: 4a5a745c2d6346950939a09aae23e1a8678a4b6fdffab72cae99161a8fa37ef8 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/rain-buy-and-sell-bitcoin.apk.cafe/ JSON API: https://api.destroy.tools/v1/check?domain=rain-buy-and-sell-bitcoin.apk.cafe Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 189,185 domains (58,452 alive under monitoring, 129,154 confirmed takedowns/dead). Site: https://phishdestroy.io