# PhishDestroy threat dossier — sczyszxxz.com ================================================================ Fetched: 2026-07-22 13:59:00 UTC Canonical: https://phishdestroy.io/domain/sczyszxxz.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain Flagging vendors: Gridinsoft Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 23.224.110.5 (US, Los Angeles) ASN: ASAS40065 CNSERVERS - CNSERVERS LLC, US Hosting org: AS40065 CNSERVERS LLC Registrar: West263 International Limited Nameservers: ns1.myhostadmin.net, ns2.myhostadmin.net, ns3.myhostadmin.net, ns4.myhostadmin.net, ns5.myhostadmin.net, ns6.myhostadmin.net Registered: 2012-07-18 Expires: 2027-07-18 Page title: 比特派钱包官网app下载-比特派钱包官方下载|比特派钱包官方入口|比特派bitpie官网下载 HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: TrustAsia Technologies, Inc. / LiteSSL RSA CA 2025 Expires: 2026-09-06 Status: INVALID chain Fingerprint: 5b65dc70286f0604b3e1657a905901ac649b5a0a6d28276f589c81ba4a0ce56f Subject Alternative Names (related infrastructure — often same operator): - m.sczyszxxz.com - www.sczyszxxz.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2012-07-18 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-06 14:19:02 UTC (by PhishDestroy tracker) Last verified: 2026-07-22 12:20:36 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f375c-7e60-744b-b530-d5e0ac6e4f58/ Wayback Machine: https://web.archive.org/web/*/sczyszxxz.com crt.sh CT logs: https://crt.sh/?q=%25.sczyszxxz.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=sczyszxxz.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/sczyszxxz.com URLhaus: https://urlhaus.abuse.ch/host/sczyszxxz.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-06 15:01:09 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] sczyszxxz.com: Confirmed Cryptocurrency Wallet Phishing Site This domain, sczyszxxz.com, has been identified as an active phishing site specifically targeting users of the Bitpie cryptocurrency wallet. The page title, "比特派钱包官网app下载-比特派钱包官方下载|比特派钱包官方入口|比特派bitpie官网下载," directly impersonates the official Bitpie wallet, suggesting an intent to deceive users into downloading malicious software or disclosing sensitive credentials. The threat type is classified as cryptocurrency phishing, a highly targeted form of fraud designed to compromise digital asset wallets and steal private keys or recovery phrases. Infrastructure analysis reveals that sczyszxxz.com was registered through West263 International Limited on July 18, 2012, though the domain's current malicious use suggests potential compromise or repurposing. The domain resolves to the IP address 23.224.110.5, a host that has not yet been flagged by any of the 95 vendors monitored by VirusTotal, indicating either recent deployment or evasion of detection mechanisms. No blocklist entries or trust scores were recorded at the time of analysis, further highlighting the domain's low visibility in threat intelligence feeds. The current status of sczyszxxz.com remains active, posing an ongoing risk to users seeking legitimate Bitpie wallet downloads. Given the absence of detections in public threat feeds, this domain may evade automated security controls. Users are strongly advised to verify the authenticity of cryptocurrency wallet websites by cross-referencing official sources and avoiding direct downloads from untrusted domains. Network administrators should consider blocking the IP address 23.224.110.5 and monitoring for connections to sczyszxxz.com within their environments. Cryptocurrency holders are reminded to enable multi-factor authentication and use hardware wallets for enhanced security. [Updates since narrative was generated:] - Public blocklists: now listed on 3 feeds ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: 5b65dc70286f0604b3e1657a905901ac649b5a0a6d28276f589c81ba4a0ce56f ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/sczyszxxz.com/ JSON API: https://api.destroy.tools/v1/check?domain=sczyszxxz.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 188,088 domains (57,533 alive under monitoring, 128,922 confirmed takedowns/dead). Site: https://phishdestroy.io