# PhishDestroy threat dossier — skate-amm.xyz ================================================================ Fetched: 2026-07-29 21:01:02 UTC Canonical: https://phishdestroy.io/domain/skate-amm.xyz/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Solana ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 4/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 186.2.175.35 (RU, Moscow) ASN: ASAS59692 IQWEB IQWeb FZ-LLC, AE Hosting org: AS59692 IQWeb FZ-LLC Registrar: Spaceship, Inc. Nameservers: launch1.spaceship.net, launch2.spaceship.net Registered: 2026-07-22 Expires: 2027-07-22 Page title: Skate AMM — Universal Multichain DEX | Single Liquidity Pool Across Solana, Hyperliquid, Sui, Arbitrum & More | skate-amm.xyz ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-10-19 Status: INVALID chain Fingerprint: 63fe80af9e95333c2d73b34b342cf0cc3131474f0c18a515e744a1d2d94d1614 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-22 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-23 12:00:41 UTC (by PhishDestroy tracker) First reported: 2026-07-23 10:07:02 UTC (abuse notice filed) Last verified: 2026-07-29 21:12:50 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f8e6a-66c8-730e-aa3a-f350cc4a2de3/ URLQuery: https://urlquery.net/report/b9d413b9-9a7b-417e-bbc9-736747ba03cf Wayback Machine: https://web.archive.org/web/*/skate-amm.xyz crt.sh CT logs: https://crt.sh/?q=%25.skate-amm.xyz Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=skate-amm.xyz AlienVault OTX: https://otx.alienvault.com/indicator/domain/skate-amm.xyz URLhaus: https://urlhaus.abuse.ch/host/skate-amm.xyz/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-23 12:02:09 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] skate-amm.xyz: Confirmed Phishing Site Analysis of skate-amm.xyz indicates that the domain was registered on July 22, 2026 through Spaceship, Inc. and is currently resolving to the IP address 186.2.175.35. The authoritative name servers for the zone are launch1.spaceship.net and launch2.spaceship.net, both consistent with the registrar's infrastructure. The site presents a valid Let's Encrypt certificate (YR1) and therefore serves HTTPS content without certificate errors, a tactic often used to increase user trust. VirusTotal records show that the domain was scanned by 91 security vendors; none of the scanners reported a detection at the time of the query, which does not imply benign intent but reflects the lack of payload or indicator matches in the current dataset. The domain appears on a single external blocklist and is actively blocked by the PhishDestroy service, confirming that at least one security community has classified it as malicious. The threat type is identified as generic phishing, and the domain remains active as of the report date, July 23, 2026. While the available intelligence does not include page titles, brand references, or detailed payload analysis, the combination of recent registration, use of a reputable TLS certificate, and inclusion on a phishing blocklist supports a high confidence assessment that the site is being used for credential harvesting or related fraudulent activity. Defenders should block network traffic to 186.2.175.35 and add skate-amm.xyz to local deny lists. Monitoring of DNS queries for the domain and its associated name servers is recommended, as is periodic re‑scanning with sandbox and URL reputation services to capture any future changes in payload behavior. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260723-4BED26 TLS cert SHA-256: 63fe80af9e95333c2d73b34b342cf0cc3131474f0c18a515e744a1d2d94d1614 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/skate-amm.xyz/ JSON API: https://api.destroy.tools/v1/check?domain=skate-amm.xyz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,508 domains (83,275 alive under monitoring, 109,716 confirmed takedowns/dead). Site: https://phishdestroy.io