# PhishDestroy threat dossier — spectrabull.ltd ================================================================ Fetched: 2026-07-29 07:14:36 UTC Canonical: https://phishdestroy.io/domain/spectrabull.ltd/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: cryptoscam ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 11/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, BitDefender, CRDF, ESET, Fortinet, G-Data, Kaspersky, Lionic, Netcraft, Sophos, VIPRE AlienVault OTX: 3 pulses (threat-intel feed mentions) Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 69.10.41.182 (US, Secaucus) ASN: AS19318 Interserver, Inc Hosting org: Interserver, Inc Registrar: Dynadot Inc Nameservers: vda1800a.trouble-free.net, vda1800b.trouble-free.net Registered: 2026-07-23 Expires: 2027-07-23 Page title: Spectra Bull – Safe investment with Spectra Bull HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE2 Expires: 2026-10-22 Status: INVALID chain Fingerprint: c347576e326267dea9e110f8cc4b5ade6e25a328e19e1ae764e38f74c4c4b36b Subject Alternative Names (related infrastructure — often same operator): - account.spectrabull.ltd - ftp.spectrabull.ltd - mail.spectrabull.ltd - pop.spectrabull.ltd - smtp.spectrabull.ltd - users.spectrabull.ltd - www.account.spectrabull.ltd - www.spectrabull.ltd - www.users.spectrabull.ltd ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-23 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-28 20:28:28 UTC (by PhishDestroy tracker) First reported: 2026-07-28 18:58:26 UTC (abuse notice filed) Last verified: 2026-07-29 06:40:51 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019faa29-fdcb-728b-8aa1-0d6e5fc6b919/ URLQuery: https://urlquery.net/report/a929ef07-ba9e-4062-951f-a96adb75e40d Wayback Machine: https://web.archive.org/web/*/spectrabull.ltd crt.sh CT logs: https://crt.sh/?q=%25.spectrabull.ltd Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=spectrabull.ltd AlienVault OTX: https://otx.alienvault.com/indicator/domain/spectrabull.ltd URLhaus: https://urlhaus.abuse.ch/host/spectrabull.ltd/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 21:06:46 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] spectrabull.ltd generic phishing campaign Analysis indicates that spectrabull.ltd was registered on July 23, 2026 through Dynadot Inc and is served by the authoritative name servers vda1800a.trouble-free.net and vda1800b.trouble-free.net. The domain resolves to the IP address 69.10.41.182, which is presently listed on three security blocklists. It is actively blocked by the PhishDestroy, MetaMask, and SEAL blocklist providers, confirming ongoing malicious use. The site presents a valid SSL certificate issued by Let’s Encrypt (identifier YE2), enabling encrypted HTTPS connections. VirusTotal scanning reports that 11 of 91 security vendors have flagged the domain as malicious, reinforcing its classification as a generic phishing threat. The domain’s status remains active, and no additional public page title or content analysis is available, leaving the specific phishing lure and targeted brand undefined. Uncertainties include the lack of visible HTTP response details, hosting provider information, and geographic location of the IP address. Defenders should immediately block spectrabull.ltd at perimeter firewalls, DNS filtering solutions, and web proxies. Adding the resolved IP 69.10.41.182 to deny lists can further reduce exposure, though the IP may be shared with legitimate services. Continuous monitoring of the domain’s DNS records and periodic re‑evaluation of VirusTotal detection counts are recommended to detect any changes in activity. Organizations that ingest blocklist feeds from PhishDestroy, MetaMask, or SEAL should verify those feeds are active, and security teams should consider flagging the registrar Dynadot Inc for potential abuse monitoring. The compiled evidence supports a high‑risk rating and warrants prompt mitigation actions. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260728-ECB33A Favicon MD5: a4080a07e3e3d2a36a4031e56c2aaa0f TLS cert SHA-256: c347576e326267dea9e110f8cc4b5ade6e25a328e19e1ae764e38f74c4c4b36b ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/spectrabull.ltd/ JSON API: https://api.destroy.tools/v1/check?domain=spectrabull.ltd Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 193,193 domains (82,961 alive under monitoring, 107,970 confirmed takedowns/dead). Site: https://phishdestroy.io