# PhishDestroy threat dossier — s87b.xyz ================================================================ Fetched: 2026-07-31 07:39:35 UTC Canonical: https://phishdestroy.io/domain/s87b.xyz/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 6/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet, LevelBlue, SOCRadar, Webroot AlienVault OTX: 3 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 103.244.148.114 (HK, Hong Kong) ASN: AS135357 HONG KONG KOWLOON TELECOMMUNICATIONS CO.,LIMITED Hosting org: Shenzhenshihong Technology Development Co., Ltd Registrar: Gname.com Pte. Ltd. Nameservers: ["ns1.1111343.com", "ns2.1111343.com", "ns3.1111343.com", "ns4.1111343.com"] Page title: s40c.top HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-09-16 Status: INVALID chain Fingerprint: 36b536bcb5b953b95a97e9715f67004b8c235c4f3f89f4de5d5fb78f8827ff51 Subject Alternative Names (related infrastructure — often same operator): - a39c.xyz - a39g.xyz - a40e.xyz - a40s.xyz - g13b.xyz - g13m.xyz - g13r.xyz - h70m.xyz - h71a.xyz - j227r.xyz - j227s.xyz - j227u.xyz - p100d.xyz - p100f.xyz - p99t.xyz ... +82 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-28 03:43:09 UTC (by PhishDestroy tracker) Last verified: 2026-07-31 08:20:23 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 03:45:08 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is s87b.xyz a phishing scam? The domain s87b.xyz is currently flagged as a high‑risk phishing site. Analysis shows it is actively hosting content that returned an HTTP 200 response, indicating a live web server. The domain was registered through Gname.com Pte. Ltd., a registrar often associated with disposable or low‑reputation registrations. Its DNS configuration points to four nameservers (ns1.1111343.com through ns4.1111343.com), a pattern commonly observed in malicious campaigns that use dynamically allocated name server clusters to evade takedown. Detection intelligence confirms that six out of ninety‑one security vendors on VirusTotal have reported the domain as malicious, and the domain appears on at least one external blocklist. PhishDestroy, a dedicated anti‑phishing service, has explicitly blocked s87b.xyz, reinforcing the assessment of active phishing activity. The presence on a blocklist and the vendor detections together demonstrate that automated scanners have identified suspicious behavior, even though the full payload or page title has not been disclosed in the available data. The limited public footprint—absence of a known SSL certificate, lack of a known brand target, and no publicly shared page title—means that the exact phishing lure cannot be confirmed without direct content inspection. Nevertheless, the convergence of a live HTTP endpoint, registrar and nameserver characteristics, and multiple vendor detections provides sufficient evidence for defenders to treat the domain as hostile. Recommended mitigation steps include adding s87b.xyz to network and DNS blocklists, configuring web proxies to deny HTTP requests to the domain, and monitoring for any outbound connections to its IP address range. Continuous re‑scanning on VirusTotal or similar platforms is advised to capture any changes in detection scores. Organizations should also educate users about the possibility of unsolicited emails that may reference this domain, given its classification as a phishing vector. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: 36b536bcb5b953b95a97e9715f67004b8c235c4f3f89f4de5d5fb78f8827ff51 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/s87b.xyz/ JSON API: https://api.destroy.tools/v1/check?domain=s87b.xyz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 196,239 domains (84,225 alive under monitoring, 27,268 confirmed neutralized). Site: https://phishdestroy.io