stacyrub[.]com
Forensic brief
PhishDestroy identifies stacyrub.com as an active generic phishing domain leveraging a crypto drainer kit to harvest wallet credentials and initiate unauthorized transfers. The domain exhibits no specific brand impersonation but deploys drainer scripts designed to siphon cryptocurrency assets upon interaction. This campaign aligns with recent tactics observed in low-effort but high-yield phishing operations targeting crypto holders. This domain resolves to IP 163.61.188.2 and was registered on April 25, 2026, through TuringSign Inc. d/b/a Cosmotown. VirusTotal analysis reveals a detection ratio of 1/95 security vendors, indicating limited but notable recognition of its malicious nature. The domain utilizes a Let's Encrypt SSL certificate to enhance credibility and has not been flagged by Google Safe Browsing (GSB) as of current intelligence. Its recent creation suggests opportunistic deployment rather than long-term infrastructure. The domain remains active and poses an elevated risk to users engaging with linked content. PhishDestroy has flagged this domain for immediate blocking and recommends verification via its platform. While GSB has not yet blacklisted stacyrub.com, its low VT detection score and recent registration indicate potential for rapid escalation. Users are advised to avoid all interactions and report any exposure. Remaining risk is moderate due to active status and drainer capabilities, necessitating proactive blocking and awareness.
Threat response pipeline
Cloudflare Radar
VirusTotal
Forensic Evidence Collectionabuse@whiteprivacy.com with forensic evidence (metadata, screenshots, PDF).Evidence capture
Domain Intelligence
TuringSign Inc. d/b/a Cosmotown
Technical details
Public blocklist status
Technologies
Technologies · 6 identified
VirusTotal consensus
Aggregated detection across 95 security vendors.
Site performance
Site performance analysis
Google PageSpeed Insights — mobile audit of stacyrub.com
Evidence & external reports
Were you affected by this site?
Were You Affected?
Report to your local authorities
Email template — registrar abuse
abuse@whiteprivacy.com, abuse@cosmotown.com
Registrar: TuringSign Inc. d/b/a Cosmotown Case: PD-PD-20260516-FF6BA5
Embed this report
About this report
About this report: stacyrub.com
This domain security report is maintained by PhishDestroy's automated threat-intelligence pipeline. Our system continuously monitors this domain across 95 security vendors on VirusTotal and 1 public blocklists.
The site displays a page titled “Stacy Magic Touch – Massage Therapist”.
stacyrub.com has been flagged by 3 security vendors as of May 17, 2026.
If you believe this listing is inaccurate, you can submit an appeal. For more information about our methodology, visit our FAQ page.