# PhishDestroy threat dossier — setmsail.cc ================================================================ Fetched: 2026-06-07 23:48:39 UTC Canonical: https://phishdestroy.io/domain/setmsail.cc/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain Flagging vendors: Forcepoint ThreatSeeker Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.97.3 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: CloudFlare, Inc. Registrar: Dynadot Inc Nameservers: ["alaric.ns.cloudflare.com", "brynne.ns.cloudflare.com"] Registered: 2026-04-28 Page title: CEX HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E8 Expires: 2026-07-17 Status: INVALID chain Fingerprint: d8279af80cedfedbde7231b05f3e312a2660ac3b93bc56fc6830cfcd1e29a416 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-28 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-28 21:01:55 UTC (by PhishDestroy tracker) First reported: 2026-04-28 18:15:20 UTC (abuse notice filed) Last verified: 2026-06-07 20:44:14 UTC Neutralised: 2026-06-06 17:33:46 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019dd53f-8434-71bd-8c73-85be9f846861/ URLQuery: https://urlquery.net/report/77fd9389-8b69-4d68-a97a-8fdb5e458c9d Wayback Machine: https://web.archive.org/web/*/setmsail.cc crt.sh CT logs: https://crt.sh/?q=%25.setmsail.cc Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=setmsail.cc AlienVault OTX: https://otx.alienvault.com/indicator/domain/setmsail.cc URLhaus: https://urlhaus.abuse.ch/host/setmsail.cc/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-28 21:03:09 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy confirms setmsail.cc as an active crypto-drain phishing site that targets digital-asset users by luring them into connecting wallets or entering private keys. The domain originated on 18 April 2026 and resolves to IP address 188.114.97.3. Registrant data shows creation through DYNADOT LLC with a Let’s Encrypt SSL certificate in place. Only 1 of 95 VirusTotal engines currently detects the threat, indicating low initial visibility yet active operation. Technical indicators align with generic phishing infrastructure: the domain is freshly registered, lacks a long-standing reputation, and returns a modest IP geolocation footprint. Low VirusTotal coverage (1/95 detections on the day of analysis) suggests evasion tactics such as fast-flux hosting or minimal payload staging. The presence of a publicly trusted SSL certificate increases perceived legitimacy and lowers user caution, a common tactic leveraged by crypto-drainers to harvest wallet credentials or seed phrases. Users must refrain from interacting with setmsail.cc or any linked pages requesting wallet connections or seed inputs. Verify any suspicious link by pasting the full URL into PhishDestroy before proceeding. Wallet owners should revoke any unintended permissions and rotate exposed keys in a secure, air-gapped environment. Report the domain immediately to your security provider and to PhishDestroy to accelerate global takedown efforts. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260428-F14F4A Favicon MD5: 79a580f05dade98a8e27204dbf962dc0 TLS cert SHA-256: d8279af80cedfedbde7231b05f3e312a2660ac3b93bc56fc6830cfcd1e29a416 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/setmsail.cc/ JSON API: https://api.destroy.tools/v1/check?domain=setmsail.cc Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 157,669 domains (41,888 alive under monitoring, 114,599 confirmed takedowns/dead). Site: https://phishdestroy.io