# PhishDestroy threat dossier — spax50b.net ================================================================ Fetched: 2026-06-26 19:48:45 UTC Canonical: https://phishdestroy.io/domain/spax50b.net/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: cryptocurrency Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users (type: content_split) (score: 1/6) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 216.198.79.65 (US, Cleveland) ASN: AS16509 Amazon.com, Inc. Hosting org: CYPRESS COMMUNICATIONS, LLC Registrar: Internet Domain Service BS Corp Nameservers: ["ns1.vercel-dns.com", "ns2.vercel-dns.com"] Registered: 2026-04-26 Page title: SPAX50B Token — AI-Powered Crypto Presale | Up to 200% Early Bonus HTTP response: 200 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-26 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-26 16:34:38 UTC (by PhishDestroy tracker) Earliest abuse rec: 2026-04-26 13:35:31 UTC — PREDATES current WHOIS registration; retained from a previous registration cycle of the same domain name Last verified: 2026-06-26 20:20:34 UTC Neutralised: 2026-06-06 17:34:51 UTC Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners Note: one or more events above predate the WHOIS creation date. This typically means the same domain name was previously registered, detected, dropped, and then re-registered by a new party. PhishDestroy preserves the full historical record for operator-attribution research even when the underlying infrastructure changes hands. ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019dc9fd-c362-74c9-a6f0-deddce53fdaf/ URLQuery: https://urlquery.net/report/09098bb5-a907-4e6f-8dc7-96089e2cfec3 Wayback Machine: https://web.archive.org/web/*/spax50b.net crt.sh CT logs: https://crt.sh/?q=%25.spax50b.net Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=spax50b.net AlienVault OTX: https://otx.alienvault.com/indicator/domain/spax50b.net URLhaus: https://urlhaus.abuse.ch/host/spax50b.net/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-26 16:37:29 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies spax50b.net as a high-risk crypto presale scam exploiting AI-powered token offers to deceive investors. The domain mimics legitimate presale sites with promises of up to 200% early bonuses, a tactic commonly used by threat actors to lure victims into depositing cryptocurrency under false pretenses. The fraudulent page titled 'SPAX50B Token — AI-Powered Crypto Presale | Up to 200% Early Bonus' is designed to appear as a credible investment opportunity, often shared via unsolicited emails or social media advertisements targeting users interested in high-yield crypto investments. This domain has not yet been widely flagged by automated security tools, increasing its potential to trick unsuspecting victims. This domain was flagged by PhishDestroy as active with a risk status of under_investigation. The domain resolved to IP address 216.198.79.65, registered anonymously through Internet Domain Service BS Corp. on April 24, 2026, a suspiciously recent registration that aligns with the onset of this phishing campaign. As of the latest scan, VirusTotal reported 0 detections out of 95 security engines, indicating that the domain has evaded immediate detection by mainstream antivirus and threat intelligence platforms. The use of a Let's Encrypt SSL certificate further enhances the domain's credibility, as it appears to provide legitimate encryption for data transmission. While no blocklist counts are currently available, the combination of these technical indicators—especially the absence of VirusTotal detections and the recent domain age—suggests this is an emerging threat with high potential for victimization. Users who have visited spax50b.net should immediately cease any interaction with the site, including attempts to participate in the advertised presale or entering personal or financial information. If any credentials or payment details were submitted, reset account passwords and contact your bank or cryptocurrency exchange to report potential fraud. Additionally, use a reputable security tool to scan your device for malware, as phishing domains often deliver payloads like keyloggers or trojans to compromised systems. Consider reporting this domain to your local cybercrime unit or through platforms like PhishDestroy to aid in its takedown. To verify the legitimacy of future crypto investment offers, cross-reference the project’s official website, social media channels, and use blockchain explorers to confirm contract addresses and liquidity details before making any transactions. [Updates since narrative was generated:] - Public blocklists: now listed on 1 feed ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260426-A7DF74 Favicon MD5: 0aeb6668eea9c3b207a64710259aa1a6 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/spax50b.net/ JSON API: https://api.destroy.tools/v1/check?domain=spax50b.net Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 170,581 domains (12,270 alive under monitoring, 157,922 confirmed takedowns/dead). Site: https://phishdestroy.io