# PhishDestroy threat dossier — spax50b.org ================================================================ Fetched: 2026-05-20 23:54:45 UTC Canonical: https://phishdestroy.io/domain/spax50b.org/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users (type: content_split) (score: 1/6) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Gridinsoft ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 64.29.17.1 (US, Walnut) ASN: AS16509 Amazon.com, Inc. Hosting org: Vercel, Inc Registrar: Internet Domain Service BS Corp Nameservers: ["ns1.vercel-dns.com", "ns2.vercel-dns.com"] Registered: 2026-04-26 Page title: SPAX50B Presale — AI-Powered Token With Early Bonus Allocation HTTP response: 200 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-26 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-26 16:34:38 UTC (by PhishDestroy tracker) Earliest abuse rec: 2026-04-26 13:37:24 UTC — PREDATES current WHOIS registration; retained from a previous registration cycle of the same domain name Last verified: 2026-05-04 19:43:13 UTC (STALE — 16 days ago, re-verify) Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners Note: one or more events above predate the WHOIS creation date. This typically means the same domain name was previously registered, detected, dropped, and then re-registered by a new party. PhishDestroy preserves the full historical record for operator-attribution research even when the underlying infrastructure changes hands. ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019dc9fd-f162-749b-bb2b-767caac979b3/ URLQuery: https://urlquery.net/report/43fa5520-c2e2-4ae0-baa4-6f6b38f63faa Wayback Machine: https://web.archive.org/web/*/spax50b.org crt.sh CT logs: https://crt.sh/?q=%25.spax50b.org Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=spax50b.org AlienVault OTX: https://otx.alienvault.com/indicator/domain/spax50b.org URLhaus: https://urlhaus.abuse.ch/host/spax50b.org/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-26 16:37:20 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies the domain spax50b.org as an active crypto drainer scam currently under investigation for impersonating a legitimate AI-powered token presale. This fraudulent landing page lures victims with promises of early bonus allocations, using deceptive tactics to extract cryptocurrency through malicious wallet connections. The operation is currently classified as an active threat, with threat actors actively promoting the domain across social media and crypto-focused platforms to drive traffic and maximize illicit gains. This domain was flagged by 0 of 95 VirusTotal vendors as of the latest scan, indicating a low initial detection rate despite clear red flags. The domain was registered through Internet Domain Service BS Corp on April 24, 2025, and resolves to IP 64.29.17.1. Its SSL certificate is issued by Let’s Encrypt, and the page title mirrors legitimate presale landing pages to enhance credibility. The absence of blocklist presence and low trust scores suggest this campaign is either newly operational or deliberately evading detection through infrastructure obfuscation. As the investigation continues, PhishDestroy recommends immediate caution when encountering spax50b.org or related links. Users should avoid interacting with the site, refrain from connecting wallets, and verify any presale offers through official project channels. Organizations and security teams are advised to monitor traffic to this domain and report findings to threat intelligence platforms. Blocking the domain at the network level and updating endpoint protection signatures can prevent exposure. PhishDestroy will continue monitoring and updating this report as new intelligence emerges. [Updates since narrative was generated:] - VirusTotal detections: now 2/91 (narrative was written when count was lower) ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260426-B2C2C9 Favicon MD5: 2e5d243eafec526ad0889ba76f7e1a63 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/spax50b.org/ JSON API: https://api.destroy.tools/v1/check?domain=spax50b.org Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 152,163 domains (43,021 alive under monitoring, 108,830 confirmed takedowns/dead). Site: https://phishdestroy.io