# PhishDestroy threat dossier — starts-suiteapp.wixstudio.com ================================================================ Fetched: 2026-04-25 12:28:02 UTC Canonical: https://phishdestroy.io/domain/starts-suiteapp.wixstudio.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 82/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Sui ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/94 security vendors flagged this domain ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 34.144.206.118 (US, Kansas City) ASN: AS396982 Google LLC Hosting org: Google Cloud Registrar: GoDaddy.com, LLC Nameservers: ["dns1.p08.nsone.net", "dns2.p08.nsone.net", "dns3.p08.nsone.net", "dns4.p08.nsone.net"] Registered: 2026-04-24 Page title: 404 Error: Page Not Found | Wix Studio HTTP response: 404 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-06-04 Status: INVALID chain Fingerprint: 79b690ec6aae60ba0de52d269638de0a570e5a2c2e467d8b649454d39b9edaab Subject Alternative Names (related infrastructure — often same operator): - wixstudio.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-24 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-24 18:00:24 UTC (by PhishDestroy tracker) Last verified: 2026-04-25 13:40:04 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019dc000-4b9f-75ee-8ea1-abef4d4142b6/ Wayback Machine: https://web.archive.org/web/*/starts-suiteapp.wixstudio.com crt.sh CT logs: https://crt.sh/?q=%25.starts-suiteapp.wixstudio.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=starts-suiteapp.wixstudio.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/starts-suiteapp.wixstudio.com URLhaus: https://urlhaus.abuse.ch/host/starts-suiteapp.wixstudio.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-24 18:00:57 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies starts-suiteapp.wixstudio.com as an active generic phishing domain under investigation for potential crypto drainer activity. The domain is currently resolving to IP 34.144.206.118 and is hosted on WixStudio, which is a common phishing hosting platform. No specific drainer kit has been publicly identified for this domain as of the latest forensic analysis, but the threat vector indicates credential theft or cryptocurrency asset exfiltration attempts through spoofed application interfaces. The domain's structure mimics legitimate suite or SaaS applications, which is characteristic of brand impersonation attacks targeting users seeking productivity software. The domain was registered through an unconfirmed registrar and utilizes a Let's Encrypt SSL certificate, which is frequently abused in phishing campaigns to establish false trust. VirusTotal currently shows 0/95 detections, indicating low signature recognition in antivirus engines as of the latest scan. The domain resolves to a Google Cloud IP (34.144.206.118), which has been flagged in multiple blocklists for hosting malicious content. Google Safe Browsing has not yet marked this domain as unsafe, and historical registration data suggests recent domain creation; however, specific creation date metadata remains unavailable through standard WHOIS queries due to privacy protections. The absence of detections does not imply safety, as generic phishing domains often evade immediate detection through low-volume, targeted campaigns. Current status shows the threat remains active with no official block by hosting providers or search engines. Response actions include continuous monitoring of the domain’s infrastructure and propagation vectors. Remaining risk is high due to the domain’s active status, lack of detections, and potential to deceive users seeking legitimate software solutions. Users are advised to avoid entering credentials or cryptocurrency wallet connections on this domain. Domain reputation services and threat intelligence platforms are urged to update their classification to mitigate silent propagation. Immediate action includes blacklisting this domain and IP at the network perimeter and educating users on verifying application authenticity through official channels. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: 79b690ec6aae60ba0de52d269638de0a570e5a2c2e467d8b649454d39b9edaab ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/starts-suiteapp.wixstudio.com/ JSON API: https://api.destroy.tools/v1/check?domain=starts-suiteapp.wixstudio.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io