# PhishDestroy threat dossier — simple-security-page--kelvinmartins81.replit.app ================================================================ Fetched: 2026-07-25 03:11:02 UTC Canonical: https://phishdestroy.io/domain/simple-security-page--kelvinmartins81.replit.app/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 71/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 10/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Ermes, ESET, Emsisoft, Fortinet, Google Safe Browsing, Kaspersky, LevelBlue, Netcraft, Webroot Public blocklists: listed on 1 independent blocklist Google Safe Browsing: FLAGGED ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 34.117.33.233 (US, Kansas City) Hosting org: AS396982 Google LLC Registrar: Replit Inc. Nameservers: NS_NOT_FOUND HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WR3 Expires: 2026-10-07 Status: INVALID chain Fingerprint: a12f2e822849b9ecff39647f2906061a178fa6c8299cbb261168850e42d826fd Subject Alternative Names (related infrastructure — often same operator): - replit.app ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-25 02:21:19 UTC (by PhishDestroy tracker) Last verified: 2026-07-25 04:30:03 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f96a4-8060-755a-9bc4-65d70072181a/ Wayback Machine: https://web.archive.org/web/*/simple-security-page--kelvinmartins81.replit.app crt.sh CT logs: https://crt.sh/?q=%25.simple-security-page--kelvinmartins81.replit.app Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=simple-security-page--kelvinmartins81.replit.app AlienVault OTX: https://otx.alienvault.com/indicator/domain/simple-security-page--kelvinmartins81.replit.app URLhaus: https://urlhaus.abuse.ch/host/simple-security-page--kelvinmartins81.replit.app/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-25 02:22:15 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] simple-security-page--kelvinmartins81.replit.app Safety Check — Analysis of simple-security-page--kelvinmartins81.replit.app as of July 25, 2026, confirms an active social-engineering phishing domain hosted on Replit Inc. infrastructure. The domain is flagged by 10 of 91 security vendors in VirusTotal scans, indicating detection by multiple engines, though the specific signatures or heuristics triggering these alerts are not detailed in available data. It appears on one security blocklist, specifically PhishDestroy, and is classified by Google Safe Browsing as engaging in social engineering, a designation typically applied to sites designed to deceive users into divulging credentials or sensitive information. Infrastructure analysis reveals the domain resolves to IP address 34.117.33.233, though the hosting provider and autonomous system details are not specified in current intelligence. The domain lacks configured nameservers, which may indicate an incomplete or misconfigured setup, though this does not preclude operational status. Registration details point to Replit Inc. as the registrar, a platform commonly used for development and hosting, which may explain the subdomain structure and naming convention. The exact content or target of the phishing page remains unconfirmed, as no page title, brand impersonation, or scam type is provided in available data. Defenders should treat this domain as high-risk based on existing detections and blocklist status. Recommended actions include blocking the domain and IP at network perimeter controls, monitoring for internal connections to the address, and reviewing logs for user interactions with the site. Further analysis of the page content and any associated payloads is advised to determine the precise threat vector and potential impact. The domain remains active as of this report, and continued monitoring is warranted. [Updates since narrative was generated:] - VirusTotal detections: now 10/91 (narrative was written when count was lower) ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: a12f2e822849b9ecff39647f2906061a178fa6c8299cbb261168850e42d826fd ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/simple-security-page--kelvinmartins81.replit.app/ JSON API: https://api.destroy.tools/v1/check?domain=simple-security-page--kelvinmartins81.replit.app Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 189,386 domains (59,697 alive under monitoring, 128,126 confirmed takedowns/dead). Site: https://phishdestroy.io