# PhishDestroy threat dossier — stellular-truffle-25b117.netlify.app ================================================================ Fetched: 2026-05-14 16:35:19 UTC Canonical: https://phishdestroy.io/domain/stellular-truffle-25b117.netlify.app/ ## VERDICT ---------------------------------------------------------------- ACTIVE THREAT — multiple warning signs Composite threat score: 55/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 19/95 security vendors flagged this domain Flagging vendors: ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, ESET, Emsisoft, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Kaspersky, LevelBlue, Lionic, Netcraft, OpenPhish, Sophos, URLQuery, VIPRE, Webroot ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 35.157.26.135 Registrar: Netlify Nameservers: NS_NOT_FOUND Registered: 2026-05-14 Page title: DocuSign - Download to View Document ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-14 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-14 18:14:39 UTC (by PhishDestroy tracker) Last verified: 2026-05-14 19:20:39 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e270c-2208-732d-bccf-6b97a6186686/ Wayback Machine: https://web.archive.org/web/*/stellular-truffle-25b117.netlify.app crt.sh CT logs: https://crt.sh/?q=%25.stellular-truffle-25b117.netlify.app Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=stellular-truffle-25b117.netlify.app AlienVault OTX: https://otx.alienvault.com/indicator/domain/stellular-truffle-25b117.netlify.app URLhaus: https://urlhaus.abuse.ch/host/stellular-truffle-25b117.netlify.app/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-14 18:15:43 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Threat intelligence identifies stellular-truffle-25b117.netlify.app as an active credential-harvesting domain posing as a legitimate login portal. This domain mimics a branded authentication page to trick users into surrendering credentials, which are then exfiltrated to attacker-controlled servers. Analysis confirms the infrastructure is hosted on IP 35.157.26.135 and leverages a DigiCert SSL certificate to appear legitimate and evade browser warnings. The domain was registered via Netlify and has already triggered detections from 19 of 95 VirusTotal security vendors, indicating elevated risk and active abuse in phishing campaigns. This domain was flagged by 19 out of 95 VirusTotal security vendors, confirming widespread recognition of its malicious intent. It resolves to IP address 35.157.26.135 and is registered through Netlify, a platform often abused by threat actors to host convincing phishing pages with minimal friction. The presence of a valid DigiCert SSL certificate further enhances its credibility, increasing the likelihood of successful deception. The campaign is currently active and represents a credible threat to users who may encounter it through email, social media, or malicious advertisements. If you visited stellular-truffle-25b117.netlify.app, assume your credentials were compromised and immediately change passwords for any accounts entered. Enable multi-factor authentication on all related accounts and review recent login activity for anomalies. Report the domain to your security team or ISP and avoid any further interaction. Consider using a password manager to detect and prevent reuse of credentials on fraudulent sites. Monitor financial accounts and enable transaction alerts if sensitive data was entered. Stay alert for follow-on phishing attempts leveraging this breach. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: dd442c5b128754be0147a96e78293bc9 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/stellular-truffle-25b117.netlify.app/ JSON API: https://api.destroy.tools/v1/check?domain=stellular-truffle-25b117.netlify.app Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 149,310 domains (36,954 alive under monitoring, 111,596 confirmed takedowns/dead). Site: https://phishdestroy.io