# PhishDestroy threat dossier — risex-exchange.xyz ================================================================ Fetched: 2026-07-21 14:33:32 UTC Canonical: https://phishdestroy.io/domain/risex-exchange.xyz/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Fake Exchange Targeted brand: Solana ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain Flagging vendors: Forcepoint ThreatSeeker Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 186.2.175.103 (BZ, Belmopan) ASN: AS59692 IQWeb FZ-LLC Hosting org: Iqweb LLC Registrar: Unstoppable Domains Inc. Nameservers: ns1.unstoppabledomains.com, ns2.unstoppabledomains.com Registered: 2026-07-20 Expires: 2027-07-20 Page title: RISEx — The Unified Exchange | Trade, Swap, Earn on Solana HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-10-18 Status: INVALID chain Fingerprint: 632bd99c772d11072cf7fd0d5507e711a8cee8ac70292651991c9d2ed8235656 Subject Alternative Names (related infrastructure — often same operator): - www.risex-exchange.xyz ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-20 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-21 03:55:27 UTC (by PhishDestroy tracker) First reported: 2026-07-21 02:02:48 UTC (abuse notice filed) Last verified: 2026-07-21 16:20:21 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f8261-1881-7325-9c88-995546f9ade4/ URLQuery: https://urlquery.net/report/79fa3efb-b682-4451-8ce9-4cba5ad07c9e Wayback Machine: https://web.archive.org/web/*/risex-exchange.xyz crt.sh CT logs: https://crt.sh/?q=%25.risex-exchange.xyz Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=risex-exchange.xyz AlienVault OTX: https://otx.alienvault.com/indicator/domain/risex-exchange.xyz URLhaus: https://urlhaus.abuse.ch/host/risex-exchange.xyz/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-21 03:57:27 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] risex-exchange.xyz — Phishing Investigation Report The domain risex-exchange.xyz was registered on 20 July 2026 through Unstoppable Domains Inc. and is delegated to the authoritative nameservers ns1.unstoppabledomains.com and ns2.unstoppabledomains.com. Within a day of registration the domain resolved to the IPv4 address 186.2.175.103, and as of the report date (21 July 2026) it remains active. VirusTotal analysis shows that one of ninety-five scanning engines flagged the domain as malicious, indicating that at least one security vendor has identified suspicious activity associated with the host. The same domain appears on a single external blocklist and is actively blocked by the PhishDestroy service, further corroborating its classification as a phishing infrastructure. The rapid creation‑to‑activation timeline, combined with the use of a blockchain‑friendly registrar, suggests an intent to exploit the brief window before takedown actions can be applied. The hosting IP address has not been publicly linked to any known benign services, and no additional telemetry such as SSL certificates, HTTP status codes, or page titles has been disclosed, leaving the exact content of the site unverified. Consequently, while the presence of a vendor detection and blocklist listing confirms a high risk posture, the precise phishing payload or targeted brand cannot be determined from the current evidence. Defenders should prioritize immediate containment by adding risex-exchange.xyz to DNS‑level deny lists and ensuring that email gateways block any URLs or attachments referencing the domain. Continuous monitoring of DNS query logs for the IP 186.2.175.103 is advised to detect lateral use of the same host. If possible, investigators should request a full content capture from the endpoint to enrich the intelligence profile and support attribution efforts. Until additional indicators are obtained, the domain should be treated as an active, high‑confidence phishing vector. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260721-D94B00 Favicon MD5: 3982d5b27add2a3c87c8dff0babe3ad9 TLS cert SHA-256: 632bd99c772d11072cf7fd0d5507e711a8cee8ac70292651991c9d2ed8235656 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/risex-exchange.xyz/ JSON API: https://api.destroy.tools/v1/check?domain=risex-exchange.xyz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 187,635 domains (57,341 alive under monitoring, 128,647 confirmed takedowns/dead). Site: https://phishdestroy.io