# PhishDestroy threat dossier — suitcat.gettoken.fun ================================================================ Fetched: 2026-07-26 06:19:56 UTC Canonical: https://phishdestroy.io/domain/suitcat.gettoken.fun/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 94/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 3/91 security vendors flagged this domain Flagging vendors: Fortinet, Gridinsoft, SOCRadar Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.96.3 (US, San Francisco) Hosting org: AS13335 Cloudflare, Inc. Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED !!! REGISTRAR INTEGRITY ALERT — NiceNIC !!! NiceNIC International: over 90% of its registered domains are associated with illegal content; documented systematic abuse-report non-response. Primary sources: https://phishdestroy.io/nicenic-real https://phishdestroy.io/nicenic-verdict Nameservers: alec.ns.cloudflare.com, erin.ns.cloudflare.com Registered: 2026-07-24 Expires: 2027-07-24 Page title: Just a moment... HTTP response: 403 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-10-22 Status: INVALID chain Fingerprint: a7868da09b56a2e8e6fb2354b8ba9417250dabea43beb4c914a2a03d0f739de0 Subject Alternative Names (related infrastructure — often same operator): - gettoken.fun ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-24 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-24 22:22:40 UTC (by PhishDestroy tracker) First reported: 2026-07-24 20:31:51 UTC (abuse notice filed) Last verified: 2026-07-26 06:40:03 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f95ca-7429-77ec-9e7d-05a94558266c/ URLQuery: https://urlquery.net/report/fdbc76be-d765-4c5d-8398-3085019c7816 Wayback Machine: https://web.archive.org/web/*/suitcat.gettoken.fun crt.sh CT logs: https://crt.sh/?q=%25.suitcat.gettoken.fun Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=suitcat.gettoken.fun AlienVault OTX: https://otx.alienvault.com/indicator/domain/suitcat.gettoken.fun URLhaus: https://urlhaus.abuse.ch/host/suitcat.gettoken.fun/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-24 22:22:57 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] suitcat.gettoken.fun — Generic Phishing Investigation The domain suitcat.gettoken.fun was registered on July 24 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and is delegated to Cloudflare name servers alec.ns.cloudflare.com and erin.ns.cloudflare.com. DNS resolution points to the IP address 188.114.96.3, an address that is currently associated with a Cloudflare‑fronted hosting environment. The domain appears on a single public blocklist and has been explicitly flagged by the PhishDestroy sinkhole, confirming that it is being used for malicious activity. VirusTotal records indicate that the domain was submitted to 91 scanning engines, none of which returned a detection at the time of analysis; this lack of detections should not be interpreted as an indication of safety, as the underlying content has not been publicly disclosed. No additional intelligence such as Safe Browsing status, Open Threat Exchange references, SSL certificate details, HTTP response codes, trust‑score metrics, page title, or evidence URLs is presently available, leaving the full scope of the phishing campaign uncertain. Given the recent creation date, the active blocklist entry, and the use of a reputable CDN provider to obscure the true hosting location, defenders should treat the domain as hostile. Recommended actions include adding suitcat.gettoken.fun to network‑level deny lists, monitoring DNS queries for the associated IP 188.114.96.3, and correlating any inbound traffic with known phishing patterns. Continuous re‑evaluation is advised, as further artifacts such as page content or additional blocklist listings may emerge, providing clearer insight into the campaign’s tactics and targets. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260724-807E1B TLS cert SHA-256: a7868da09b56a2e8e6fb2354b8ba9417250dabea43beb4c914a2a03d0f739de0 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/suitcat.gettoken.fun/ JSON API: https://api.destroy.tools/v1/check?domain=suitcat.gettoken.fun Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,704 domains (65,338 alive under monitoring, 128,816 confirmed takedowns/dead). Site: https://phishdestroy.io