# PhishDestroy threat dossier — social.kikoba.app ================================================================ Fetched: 2026-07-30 06:01:01 UTC Canonical: https://phishdestroy.io/domain/social.kikoba.app/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 73/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 151.101.1.195 (CA, Montreal) ASN: AS54113 Fastly, Inc. Hosting org: Fastly, Inc. Registrar: Namecheap Inc. Nameservers: ["ns1.lockwood.co.tz", "ns2.lockwood.co.tz"] Page title: Invalid Dynamic Link HTTP response: 301 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WR3 Expires: 2026-09-11 Status: INVALID chain Fingerprint: b2ef6286ccf9d9d89556149784fd5a4d8540d6ea18cdcacc663192d45b192eb9 Subject Alternative Names (related infrastructure — often same operator): - a.cdn01-bc.redlink.com.ar - admin.dream-more.kr - app.preprod.komence.io - app.shinelegshop.com - app.smileweb.id - apstradinghub.com - artisan.travauxdemain.fr - auth.loveyourwallet.com - auth.quantiliom.com - autoklaar.com - beta.hearingloopdesigner.com - bitacoras.grupocurman.com - cricketiq.co - crm.monitorcm.se - dashboard.digimaxad.com ... +84 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-28 08:23:09 UTC (by PhishDestroy tracker) Last verified: 2026-07-30 04:20:21 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 08:24:39 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] social.kikoba.app — Phishing Investigation Report The domain social.kikoba.app was observed on July 28, 2026 as an active generic phishing site. Registration information indicates the domain was created through Namecheap Inc., and its authoritative DNS is served by ns1.lockwood.co.tz and ns2.lockwood.co.tz. HTTP requests to the host return a 301 redirect, suggesting an intentional forwarding mechanism that may be used to conceal the final phishing payload. The domain appears on a single security blocklist and has been explicitly blocked by the PhishDestroy service, confirming that at least one external mitigation platform has taken action against it. VirusTotal records show that the site was scanned by 91 anti‑malware vendors; none of those vendors raised a detection at the time of the scan, but the absence of alerts does not constitute evidence of benign behavior and should be interpreted as a lack of current signatures rather than a safety guarantee. No additional intelligence such as Safe Browsing warnings, Open Threat Exchange alerts, SSL certificate details, or page‑title metadata is presently available. Consequently, the precise content and target of the phishing campaign remain uncertain, and the lack of visible branding or victim‑specific lure limits attribution. Defenders should continue to monitor the domain for changes in DNS configuration, HTTP response codes, or the emergence of detections in threat‑intelligence feeds. Organizations are advised to enforce strict URL filtering for any sub‑domains of kikoba.app, especially those hosted under the lockwood.co.tz nameserver pair, and to incorporate the domain into existing phishing‑blocking policies. Incident response teams should treat any user‑reported interactions with social.kikoba.app as potentially malicious, isolate affected accounts, and gather forensic evidence promptly. Ongoing vigilance is required, as the active status and limited blocklist presence suggest the campaign may still be in an early deployment phase. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: b2ef6286ccf9d9d89556149784fd5a4d8540d6ea18cdcacc663192d45b192eb9 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/social.kikoba.app/ JSON API: https://api.destroy.tools/v1/check?domain=social.kikoba.app Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,581 domains (93,406 alive under monitoring, 99,913 confirmed takedowns/dead). Site: https://phishdestroy.io