# PhishDestroy threat dossier — rainbow-wallet.com.mx ================================================================ Fetched: 2026-07-23 21:05:47 UTC Canonical: https://phishdestroy.io/domain/rainbow-wallet.com.mx/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Crypto Drainer Targeted brand: Rainbow Wallet ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain Flagging vendors: Fortinet Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 209.74.82.247 (SG, Singapore) ASN: AS22612 Namecheap, Inc. Hosting org: Namecheap Inc Registrar: Registrar.eu Nameservers: a.dnspod.com, b.dnspod.com, c.dnspod.com Registered: 2026-07-10 Expires: 2027-07-10 Page title: Rainbow Wallet — Official Platform HTTP response: 302 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE1 Expires: 2026-10-09 Status: INVALID chain Fingerprint: 322e7faf3b2985ef4ea4d1e5b8250c7068340f85df4ac6919f3124865d620dca Subject Alternative Names (related infrastructure — often same operator): - www.rainbow-wallet.com.mx ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-10 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-13 09:13:29 UTC (by PhishDestroy tracker) Last verified: 2026-07-23 20:20:25 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f5a52-285c-75c5-93dc-370b5edffcb1/ Wayback Machine: https://web.archive.org/web/*/rainbow-wallet.com.mx crt.sh CT logs: https://crt.sh/?q=%25.rainbow-wallet.com.mx Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=rainbow-wallet.com.mx AlienVault OTX: https://otx.alienvault.com/indicator/domain/rainbow-wallet.com.mx URLhaus: https://urlhaus.abuse.ch/host/rainbow-wallet.com.mx/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-13 09:20:21 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] rainbow-wallet.com.mx — Crypto Drainer Investigation Report rainbow-wallet.com.mx was registered on 2026-07-10 through Registrar.eu and is currently pointing to the IPv4 address 209.74.82.247. The domain is served by three DNSPod name servers (a.dnspod.com, b.dnspod.com, c.dnspod.com). Internal classification tags the domain as a crypto‑drainer, and the risk level remains under investigation while the indicator status is active. No public content has been retrieved, and there is no evidence of a specific payload or payment‑processing page. The short age of the domain, combined with the use of a reputable DNS provider, suggests a deliberately staged infrastructure rather than a compromised legacy site. Analysts should monitor DNS resolution for changes, query the IP for additional services, and add the domain to blocklists used by perimeter defenses. Network sensors should flag outbound connections to 209.74.82.247, especially any traffic attempting to interact with cryptocurrency wallets. Because the domain’s activity window is narrow, retrospective logs from before 2026‑07‑10 are unlikely to contain relevant events, but continuous logging is advised to capture any future malicious transactions. Further investigation is required to determine whether the site hosts a phishing front‑end, a malicious downloader, or a command‑and‑control endpoint. Until such details are uncovered, precautionary blocking and heightened alerting are recommended. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: b01122b8efe9b9022ddb161443198081 TLS cert SHA-256: 322e7faf3b2985ef4ea4d1e5b8250c7068340f85df4ac6919f3124865d620dca ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/rainbow-wallet.com.mx/ JSON API: https://api.destroy.tools/v1/check?domain=rainbow-wallet.com.mx Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 188,947 domains (58,596 alive under monitoring, 128,729 confirmed takedowns/dead). Site: https://phishdestroy.io