# PhishDestroy threat dossier — smartlysniper.com ================================================================ Fetched: 2026-05-25 10:54:45 UTC Canonical: https://phishdestroy.io/domain/smartlysniper.com/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Solana Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users (type: status_split) (score: 2/6) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/92 security vendors flagged this domain ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 104.21.35.66 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com Nameservers: penny.ns.cloudflare.com, scott.ns.cloudflare.com Registered: 2026-05-10 Page title: Swifty · Solana Sniper HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E7 Expires: 2026-08-08 Status: INVALID chain Fingerprint: fe55ee940841be6b3313555ccfc0b40a08eb036a55f77de37f6f391c81aedf47 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-10 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-14 21:52:10 UTC (by PhishDestroy tracker) First reported: 2026-05-14 18:52:49 UTC (abuse notice filed) Last verified: 2026-05-25 13:33:16 UTC Neutralised: 2026-05-15 01:45:37 UTC Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e27d3-1063-745e-a8e2-ba541e31cd9e/ URLQuery: https://urlquery.net/report/bb745091-90ee-4ae9-809d-98dea76c9bbc Wayback Machine: https://web.archive.org/web/*/smartlysniper.com crt.sh CT logs: https://crt.sh/?q=%25.smartlysniper.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=smartlysniper.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/smartlysniper.com URLhaus: https://urlhaus.abuse.ch/host/smartlysniper.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-14 21:52:56 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Smartlysniper.com is a recently activated domain designed to mimic trusted online platforms and trick visitors into entering sensitive login credentials or payment information. Evidence shows it is part of a credential harvesting campaign aimed at capturing usernames, passwords, and financial details under false pretenses. Users who interact with this site risk immediate account compromise and potential financial loss. This domain is not a legitimate service and should be treated as malicious from the outset. PhishDestroy identifies smartlysniper.com as a live credential harvesting operation active since its creation on May 10, 2026. Registered through PDR Ltd. d/b/a PublicDomainRegistry.com, it resolves to IP address 104.21.35.66 and uses a Let’s Encrypt SSL certificate to appear trustworthy. Despite zero detections on VirusTotal (0/95 engines), behavior analysis confirms it hosts spoofed login forms and likely redirects users to external phishing pages. The combination of recent registration, low detection rate, and absence of legitimate content strongly suggests malicious intent. If you visited smartlysniper.com, cease any data entry immediately and check your accounts for unauthorized access. Do not click any links or download files from the site. If you entered credentials, change passwords on other accounts where you reused the same login details and enable multi-factor authentication. Report the domain to your IT team or local cybercrime unit. Remove browser cookies and site data associated with smartlysniper.com to prevent future redirects. Stay alert: cybercriminals often reuse domains like this in follow-on attacks targeting the same users. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260514-F33530 Favicon MD5: 73bc65841eb63fdc05926d0928087306 TLS cert SHA-256: fe55ee940841be6b3313555ccfc0b40a08eb036a55f77de37f6f391c81aedf47 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/smartlysniper.com/ JSON API: https://api.destroy.tools/v1/check?domain=smartlysniper.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 152,979 domains (39,600 alive under monitoring, 112,923 confirmed takedowns/dead). Site: https://phishdestroy.io