# PhishDestroy threat dossier — res-blindbox-portal.pages.dev ================================================================ Fetched: 2026-05-03 05:35:09 UTC Canonical: https://phishdestroy.io/domain/res-blindbox-portal.pages.dev/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 65/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/94 security vendors flagged this domain ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.96.3 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: CloudFlare, Inc. Registrar: Cloudflare, Inc. Nameservers: bradley.ns.cloudflare.com, hera.ns.cloudflare.com Registered: 2026-04-21 Page title: Blind Box Portal HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E8 Expires: 2026-07-20 Status: INVALID chain Fingerprint: 421ddb57a6f689a62e8e513391b4f5e9ee64d4c4ee23551dcdedb7581ff5b2ae ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-21 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-21 08:58:35 UTC (by PhishDestroy tracker) Last verified: 2026-04-29 07:40:15 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019dae9c-9bcf-721e-a083-6061ea1ce5d2/ Wayback Machine: https://web.archive.org/web/*/res-blindbox-portal.pages.dev crt.sh CT logs: https://crt.sh/?q=%25.res-blindbox-portal.pages.dev Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=res-blindbox-portal.pages.dev AlienVault OTX: https://otx.alienvault.com/indicator/domain/res-blindbox-portal.pages.dev URLhaus: https://urlhaus.abuse.ch/host/res-blindbox-portal.pages.dev/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-21 08:59:10 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] res-blindbox-portal.pages.dev is currently active in a credential harvesting phishing campaign targeting users of blind box services or related e-commerce platforms. The domain masquerades as a legitimate blind box retailer or portal, likely aiming to trick victims into entering sensitive login credentials or payment details under the guise of order verification or account access. This phishing infrastructure is hosted on Cloudflare Pages and leverages trusted services to evade detection, making it critical for users to verify URLs and avoid entering personal information on unsolicited pages. This domain was flagged by 0 of 95 VirusTotal vendors at the time of analysis, indicating a low detection rate due to its use of legitimate infrastructure such as Cloudflare’s Pages service and a Let’s Encrypt SSL certificate. The domain resolves to IP address 188.114.96.3, which is associated with Cloudflare’s hosting network. Registration details indicate the use of Cloudflare, Inc. as the registrar, with no additional blocklist entries recorded at this stage. The domain is a subdomain under pages.dev, a legitimate Cloudflare Pages domain, which is frequently abused in phishing campaigns due to its trusted status and ease of deployment. Trust scores and historical data remain under investigation, but the lack of vendor detections suggests a recently activated or rapidly evolving threat. The current status of res-blindbox-portal.pages.dev remains active, with no signs of takedown or mitigation as of this report. Given the low detection rate and the use of reputable infrastructure, the risk of successful phishing attempts remains moderate to high, particularly for users expecting legitimate blind box services. Recommendations include blocking the domain at the network level, avoiding interaction with unsolicited links claiming to represent blind box retailers, and verifying any requests for login credentials or payments through official channels. Users should also report suspicious activity to their security teams or platform providers to aid in rapid threat containment. Monitoring for similar domains leveraging Cloudflare Pages or Let’s Encrypt certificates is advised to preempt potential copycat campaigns. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 47cd79fa2df1f5ec0cefec2baa548577 TLS cert SHA-256: 421ddb57a6f689a62e8e513391b4f5e9ee64d4c4ee23551dcdedb7581ff5b2ae ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/res-blindbox-portal.pages.dev/ JSON API: https://api.destroy.tools/v1/check?domain=res-blindbox-portal.pages.dev Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 144,880 domains (52,889 alive under monitoring, 91,737 confirmed takedowns/dead). Site: https://phishdestroy.io