# PhishDestroy threat dossier — ring-protocol.com ================================================================ Fetched: 2026-07-29 14:57:26 UTC Canonical: https://phishdestroy.io/domain/ring-protocol.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: cryptocurrency Targeted brand: Drift ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 186.2.175.35 (BZ, Belmopan) ASN: AS59692 IQWeb FZ-LLC Hosting org: Iqweb LLC Registrar: Fewmoretaps OU d/b/a Trustname.com !!! REGISTRAR INTEGRITY ALERT — Trustname / Fewmoretaps OU !!! Trustname (IANA #4318) is a shell company declaring EUR 120 annual revenue, 1 employee, negative equity, Belarusian ownership. Explicitly advertises itself as 'bulletproof' in its DNS TXT records. Primary source: https://phishdestroy.io/trustname-bulletproof-exposed Nameservers: ares.trustname.com, ns1.anycastdns.cz, ns2.anycastdns.cz, zeus.trustname.com Registered: 2026-07-24 Expires: 2027-07-24 Page title: Ring Protocol — Multi-Chain Liquidity Protocol | Ethereum · Arbitrum · Base HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-10-22 Status: INVALID chain Fingerprint: f91e7ef5b2c41330db4f7dc5141f47154a1c59511d7665c0bde1b27b6fdd5fce Subject Alternative Names (related infrastructure — often same operator): - www.ring-protocol.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-24 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-28 19:55:36 UTC (by PhishDestroy tracker) First reported: 2026-07-28 18:17:58 UTC (abuse notice filed) Last verified: 2026-07-29 16:20:22 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa9df-d24d-703a-a1b4-bdb8f12a6283/ URLQuery: https://urlquery.net/report/02e5d532-d3cc-4689-abe5-fc874ef1f6f2 Wayback Machine: https://web.archive.org/web/*/ring-protocol.com crt.sh CT logs: https://crt.sh/?q=%25.ring-protocol.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=ring-protocol.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/ring-protocol.com URLhaus: https://urlhaus.abuse.ch/host/ring-protocol.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 20:01:51 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is ring-protocol.com a Phishing Site for Crypto or Wallet Scams? Analysis of ring-protocol.com indicates a recently registered domain exhibiting infrastructure patterns consistent with phishing activity. The domain was created on July 24, 2026, and is currently active. It is registered through Fewmoretaps OU, operating under Trustname.com, a registrar frequently associated with domains later flagged for malicious use. The domain resolves to the IP address 186.2.175.35, and its nameservers include ares.trustname.com, ns1.anycastdns.cz, ns2.anycastdns.cz, and zeus.trustname.com, suggesting a reliance on hosting and DNS providers commonly utilized in low-reputation or bulletproof infrastructure. As of July 28, 2026, ring-protocol.com appears on one security blocklist, specifically PhishDestroy, which has flagged it as potentially malicious. No other public blocklists or threat intelligence feeds have reported the domain at this time. A VirusTotal scan conducted by 91 vendors returned no detections; however, this absence does not confirm the domain's safety, as phishing domains often evade detection during early stages of deployment. The domain's name, 'ring-protocol,' implies a potential association with cryptocurrency, blockchain protocols, or digital wallet services, though no specific brand or service has been confirmed as the target. The exact content of the site remains unanalyzed, and no page title, phishing kit, or scam type has been identified in available intelligence. Defenders are advised to treat this domain as suspicious based on its recent registration, hosting infrastructure, and blocklist presence. Network-level blocking or monitoring of traffic to 186.2.175.35 is recommended pending further analysis. Additional scrutiny, including SSL certificate inspection and behavioral analysis of any observed traffic, may provide further indicators of compromise. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260728-2EFF95 Favicon MD5: c7acd44c40476490de8e69baa205e8e8 TLS cert SHA-256: f91e7ef5b2c41330db4f7dc5141f47154a1c59511d7665c0bde1b27b6fdd5fce ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/ring-protocol.com/ JSON API: https://api.destroy.tools/v1/check?domain=ring-protocol.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,481 domains (83,248 alive under monitoring, 109,716 confirmed takedowns/dead). Site: https://phishdestroy.io