# PhishDestroy threat dossier — registartion-usdai.com ================================================================ Fetched: 2026-06-20 23:41:28 UTC Canonical: https://phishdestroy.io/domain/registartion-usdai.com/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 89/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain URLQuery: 2 detections Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.97.3 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: CloudFlare, Inc. Registrar: CNOBIN INFORMATION TECHNOLOGY LIMITED Nameservers: ["elsa.ns.cloudflare.com", "kirk.ns.cloudflare.com"] Registered: 2026-04-28 Page title: $CHIP Portal | USD AI ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E8 Expires: 2026-07-25 Status: INVALID chain Fingerprint: 7d43c582c291a565861bfccb06d6ebdfce9f021e2a9868346eadfd3156635167 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-28 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-28 16:51:39 UTC (by PhishDestroy tracker) Earliest abuse rec: 2026-04-28 13:53:45 UTC — PREDATES current WHOIS registration; retained from a previous registration cycle of the same domain name Last verified: 2026-06-21 00:20:43 UTC Neutralised: 2026-05-14 04:32:07 UTC Current status: taken down (registrar suspended or DNS dead) Note: one or more events above predate the WHOIS creation date. This typically means the same domain name was previously registered, detected, dropped, and then re-registered by a new party. PhishDestroy preserves the full historical record for operator-attribution research even when the underlying infrastructure changes hands. ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019dd45a-7bf6-7280-ac91-fe02edbc802b/ URLQuery: https://urlquery.net/report/e9d76174-fb50-4acb-9e2e-33bf8a6c695a Wayback Machine: https://web.archive.org/web/*/registartion-usdai.com crt.sh CT logs: https://crt.sh/?q=%25.registartion-usdai.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=registartion-usdai.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/registartion-usdai.com URLhaus: https://urlhaus.abuse.ch/host/registartion-usdai.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-28 16:53:13 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] registartion-usdai.com mimics a legitimate $CHIP Portal for USD AI, creating a convincing trap for visitors expecting a genuine cryptocurrency or financial service interface. This domain poses as an official portal but is designed to harvest sensitive credentials or inject malware under the guise of a $CHIP-related platform. The page title intentionally mirrors that of a real service to deceive users into lowering their guard, making it a high-risk imitation rather than a random phishing attempt. This domain was flagged by PhishDestroy during routine threat monitoring. Key indicators include 0 detections on VirusTotal as of submission, a creation date of April 26, 2026, and registration through CNOBIN INFORMATION TECHNOLOGY LIMITED. The domain resolves to IP address 188.114.97.3 and uses a Let’s Encrypt SSL certificate, which further lends an air of legitimacy to the fraudulent site. Despite its recent registration, the domain has already been associated with active phishing activity targeting users interested in USD AI or $CHIP transactions. If you visited registartion-usdai.com, immediately cease any interaction with the page. Do not enter credentials, download files, or click on any links. Clear your browser cache and run a full malware scan using reputable antivirus software. If you provided login details, change passwords on all accounts using the same credentials and enable two-factor authentication. Report the incident to your IT security team or relevant platform support. Monitor financial accounts closely for unauthorized activity. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260428-56BEC9 Favicon MD5: 5ce77b4d942900dd294edf411754a760 TLS cert SHA-256: 7d43c582c291a565861bfccb06d6ebdfce9f021e2a9868346eadfd3156635167 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/registartion-usdai.com/ JSON API: https://api.destroy.tools/v1/check?domain=registartion-usdai.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 167,040 domains (14,902 alive under monitoring, 151,820 confirmed takedowns/dead). Site: https://phishdestroy.io