# PhishDestroy threat dossier — site-peltrix.life ================================================================ Fetched: 2026-08-01 10:18:24 UTC Canonical: https://phishdestroy.io/domain/site-peltrix.life/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 93/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 5/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 104.21.23.228 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: NameCheap, Inc. Nameservers: harmony.ns.cloudflare.com, zahir.ns.cloudflare.com Registered: 2025-12-05 Expires: 2026-12-05 Page title: 404 Not Found HTTP response: 404 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-09-03 Status: INVALID chain Fingerprint: 2a75207c6e24b158dd42606745a5afc9641a543e1c3c8fa92ecc57456a283e93 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-12-05 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-24 16:13:38 UTC (by PhishDestroy tracker) First reported: 2026-07-24 14:18:08 UTC (abuse notice filed) Last verified: 2026-08-01 08:20:30 UTC Neutralised: 2026-07-25 00:28:21 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f9479-242b-716c-839a-b33106ca1e0d/ URLQuery: https://urlquery.net/report/2fbbd681-5e2f-4088-86e9-17db01280096 Wayback Machine: https://web.archive.org/web/*/site-peltrix.life crt.sh CT logs: https://crt.sh/?q=%25.site-peltrix.life Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=site-peltrix.life AlienVault OTX: https://otx.alienvault.com/indicator/domain/site-peltrix.life URLhaus: https://urlhaus.abuse.ch/host/site-peltrix.life/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-24 16:13:51 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] site-peltrix.life Generic Phishing Campaign The domain site-peltrix.life was registered on December 5, 2025 through NameCheap, Inc. and is currently served by Cloudflare nameservers harmony.ns.cloudflare.com and zahir.ns.cloudflare.com. DNS resolution points to the IP address 104.21.23.228, which is the only observable hosting indicator. The domain appears on a single public blocklist, PhishDestroy, confirming that at least one security‑focused feed has flagged it as malicious. VirusTotal records show that the domain has been scanned by 91 antivirus or URL‑reputation vendors; none of those scanners have generated a detection at the time of analysis. While the absence of detections does not imply safety, it indicates that automated signatures have not yet identified the payload or landing page as malicious. The domain’s risk level is listed as “under investigation” and its operational status is active, meaning the site is reachable and may be serving phishing content. No additional intelligence such as a page title, brand target, SSL certificate details, or HTTP response codes is currently available, limiting the depth of content‑level analysis. Defenders should therefore treat the domain as potentially hostile: block the domain and its associated IP at the network perimeter, add it to internal DNS blocklists, and monitor for any traffic to the Cloudflare nameservers that may indicate compromised client activity. Continuous re‑scanning on multi‑vendor platforms is recommended to capture any future detection updates, and any observed credential harvesting attempts should be investigated as part of broader phishing response procedures. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260724-9882CA TLS cert SHA-256: 2a75207c6e24b158dd42606745a5afc9641a543e1c3c8fa92ecc57456a283e93 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/site-peltrix.life/ JSON API: https://api.destroy.tools/v1/check?domain=site-peltrix.life Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,902 domains (90,831 alive under monitoring, 27,319 confirmed neutralized). Site: https://phishdestroy.io