# sand-protocol.com — SUSPICIOUS > sand-protocol.com is a confirmed phishing domain detected by PhishDestroy. Multiple security vendors have flagged this domain. Our analysis includes WHOIS records, SSL data, and blocklist cross-referencing. ## Summary Threat Overview The domain sand-protocol.com has been flagged as a phishing threat. PhishDestroy's automated scanning systems detected multiple risk indicators associated with this domain. Detection Details This domain was identified through a combination of automated analysis, community reports, and cross-referencing with global threat intelligence feeds including VirusTotal, Google Safe Browsing, and 50+ specialized blocklists. Risk Indicators - Domain registered on com TLD - Domain length: 17 characters - Vt Detected Stay Safe Always verify URLs before entering credentials. Use a password manager to avoid typing passwords on fake sites. Enable two-factor authentication wherever possible. ## Threat Details - Verdict: SUSPICIOUS - Site status: alive (HTTP 530) - Page title: The Sandbox - Airdrop is now live! ## Domain Intelligence - Registered: 2026-02-21 07:01:08 - IP: 188.114.97.3 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - SSL Issuer: WE1 ## Detection Status - VirusTotal: 2 vendors flagged Vendors: ["Fortinet", "Gridinsoft"] - Google Safe Browsing: clean - Blocklists: 4 hits Lists: ["PhishDestroy", "Polkadot", "Enkrypt", "Codeesura"] ## Evidence - Screenshot: https://urlscan.io/screenshots/01998854-373d-7297-86e5-cc8c2506832e.png - PhishDestroy: https://phishdestroy.io/domain/sand-protocol.com/ - LLM endpoint: https://phishdestroy.io/domain/sand-protocol.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/sand-protocol.com/ Last updated: 2026-03-19