# PhishDestroy threat dossier — stakesone.site ================================================================ Fetched: 2026-07-23 03:37:33 UTC Canonical: https://phishdestroy.io/domain/stakesone.site/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Crypto Drainer Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 3/91 security vendors flagged this domain Flagging vendors: Fortinet, Kaspersky, SOCRadar Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 104.21.13.121 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: Ultahost, Inc. Nameservers: dion.ns.cloudflare.com, sky.ns.cloudflare.com Registered: 2026-06-10 Expires: 2027-06-10 Page title: Stakesone | Decentralized Web3 Gambling Site with Provable Trust HTTP response: 666 (custom cloaking code — see Cloaking above) ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-09-09 Status: INVALID chain Fingerprint: 97f27d2d49283f0e77e056c7497c5da69de6be93f37f70045d20b80a8ebf6126 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-06-10 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-12 18:20:45 UTC (by PhishDestroy tracker) First reported: 2026-07-12 21:33:16 UTC (abuse notice filed) Last verified: 2026-07-23 04:20:26 UTC Neutralised: 2026-07-21 03:52:02 UTC Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f5721-2dfb-7524-bd43-fa95498b7ebc/ URLQuery: https://urlquery.net/report/d8f36a87-bb8f-48fb-acd6-cb8f2ac11a6e Wayback Machine: https://web.archive.org/web/*/stakesone.site crt.sh CT logs: https://crt.sh/?q=%25.stakesone.site Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=stakesone.site AlienVault OTX: https://otx.alienvault.com/indicator/domain/stakesone.site URLhaus: https://urlhaus.abuse.ch/host/stakesone.site/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-12 18:34:40 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] stakesone.site Crypto Drainer – Active Threat The domain stakesone.site was registered on June 10, 2026 through Ultahost, Inc. and is currently active. DNS resolution points to the Cloudflare edge address 104.21.13.121, with authoritative name servers dion.ns.cloudflare.com and sky.ns.cloudflare.com. No detections have been reported on VirusTotal (0/95), indicating that the site has not yet been flagged by automated scanners. Infrastructure analysis shows the domain is hosted behind Cloudflare’s CDN, which masks the origin server and provides rapid DNS propagation. The use of two distinct Cloudflare name servers suggests a standard configuration rather than a bespoke hosting setup. The IP address belongs to a Cloudflare edge node, making geolocation and attribution to a specific ASN or country difficult. Threat intelligence classifies stakesone.site as a crypto drainer, a variant of phishing that typically lures victims into authorizing cryptocurrency transactions or exposing private keys. While no payload samples have been publicly released, the recent registration date and immediate activation are consistent with campaigns that deploy short‑lived domains to evade reputation systems. The absence of VirusTotal detections does not rule out malicious intent, as many crypto‑drainer kits employ obfuscation techniques that evade static scanners. Defenders should treat the domain as high‑priority for monitoring. Network sensors should flag any outbound connections to 104.21.13.121, especially those involving wallet software or blockchain APIs. Email filters should scrutinize messages containing links to stakesone.site, and endpoint controls ought to block execution of unauthorized wallet actions originating from this host. Continuous re‑scanning of the domain on multiple sandbox platforms is advised to capture any evolving payloads. [Updates since narrative was generated:] - VirusTotal detections: now 3/91 (narrative was written when count was lower) ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260712-094A0E TLS cert SHA-256: 97f27d2d49283f0e77e056c7497c5da69de6be93f37f70045d20b80a8ebf6126 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/stakesone.site/ JSON API: https://api.destroy.tools/v1/check?domain=stakesone.site Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 188,607 domains (58,669 alive under monitoring, 128,313 confirmed takedowns/dead). Site: https://phishdestroy.io