# PhishDestroy threat dossier — s88q.xyz ================================================================ Fetched: 2026-07-29 13:26:54 UTC Canonical: https://phishdestroy.io/domain/s88q.xyz/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 14/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, LevelBlue, Lionic, SOCRadar, Sophos, VIPRE, Webroot AlienVault OTX: 3 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 103.244.148.113 (HK, Hong Kong) ASN: AS135357 HONG KONG KOWLOON TELECOMMUNICATIONS CO.,LIMITED Hosting org: Shenzhenshihong Technology Development Co., Ltd Registrar: Gname.com Pte. Ltd. Nameservers: ["ns1.1111343.com", "ns2.1111343.com", "ns3.1111343.com", "ns4.1111343.com"] ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-09-16 Status: INVALID chain Fingerprint: e6378666e2b0c862db5c09da83b8dba83d44edd604be2fb4a883b3acbc88f9ae Subject Alternative Names (related infrastructure — often same operator): - h25d.top - h25z.top - h26a.top - h26b.top - h26c.top - h26e.top - h26f.top - h71o.xyz - h72h.xyz - h72j.xyz - h72l.xyz - h72p.xyz - h73c.xyz - h73i.xyz - r22t.xyz ... +83 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-28 03:53:08 UTC (by PhishDestroy tracker) Last verified: 2026-07-29 12:34:09 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 03:55:06 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] s88q.xyz – High‑Risk Generic Phishing Site Detected The domain s88q.xyz is currently listed on a single security blocklist and remains active as of the 28 July 2026 reporting date. DNS resolution is provided by four authoritative name servers (ns1.1111343.com, ns2.1111343.com, ns3.1111343.com, ns4.1111343.com), indicating a multi‑server configuration that may be used to increase resilience. The registrar information shows the domain was registered through Gname.com Pte. Ltd., a provider often seen in malicious registrations. An HTTP GET request returns a 200 OK status, confirming that a web service is reachable at the domain. VirusTotal analysis records 14 of 91 security vendors flagging the domain as malicious, reinforcing the suspicion of abuse. The domain is also explicitly blocked by the PhishDestroy feed, which classifies it as a high‑risk phishing resource. No additional intelligence such as page title, SSL certificate details, hosting IP address, or geographic ASN is available in the current dataset, leaving the exact phishing campaign vector and target brand undefined. Consequently, defenders cannot ascertain the specific credential‑stealing technique or victim profile used by this site. Because no SSL/TLS fingerprint or certificate transparency record has been published, it is unclear whether the site employs HTTPS, which could affect detection by TLS inspection tools. The lack of publicly disclosed hosting IP prevents geolocation or ASN‑based filtering, so network‑level defenders should rely on domain‑based controls. Organizations employing email security gateways should treat any inbound messages referencing s88q.xyz as malicious and quarantine them. Threat‑intel teams are encouraged to submit any observed payloads to shared analysis platforms to improve detection coverage. Given the observed indicators—blocklist presence, multi‑server name resolution, registrar choice, HTTP 200 response, and multiple vendor detections—security teams should immediately add s88q. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: e6378666e2b0c862db5c09da83b8dba83d44edd604be2fb4a883b3acbc88f9ae ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/s88q.xyz/ JSON API: https://api.destroy.tools/v1/check?domain=s88q.xyz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,475 domains (83,242 alive under monitoring, 109,716 confirmed takedowns/dead). Site: https://phishdestroy.io