# PhishDestroy threat dossier — sun3322.com ================================================================ Fetched: 2026-07-29 08:07:57 UTC Canonical: https://phishdestroy.io/domain/sun3322.com/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 75/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 14/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, BitDefender, CRDF, CyRadar, Emsisoft, Forcepoint ThreatSeeker, Fortinet, G-Data, LevelBlue, Lionic, Netcraft, SOCRadar, Sophos, Webroot AlienVault OTX: 3 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 168.76.223.186 (ZA, Bloemfontein) ASN: AS137951 ASLINE LIMITED Hosting org: Free State Education Department Registrar: Realtime Register B.V. Nameservers: ["ns1.domainnamedns.com", "ns2.domainnamedns.com"] Page title: 太阳城澳门 (中国)官方网站 HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R13 Expires: 2026-08-09 Status: INVALID chain Fingerprint: 02d0e6a9280b346b0293f82abfa965aa51a5a3d75b5d2ccf33ffd89525441871 Subject Alternative Names (related infrastructure — often same operator): - m.sun0039.com - m.sun018.com - m.sun206.com - m.sun225.com - m.sun2277.com - m.sun235.com - m.sun241.com - m.sun260.com - m.sun2828.com - m.sun298.com - m.sun3309.com - m.sun3322.com - m.sun3655.com - m.sun486.com - m.sun5088.com ... +83 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-28 11:03:09 UTC (by PhishDestroy tracker) Last verified: 2026-07-29 09:34:09 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 11:04:19 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] sun3322.com — Phishing Investigation Report Analysis of sun3322.com as of July 28, 2026 indicates that the domain is currently active and serving HTTP responses with status code 200. The domain is registered through Realtime Register B.V. and resolves to the authoritative name servers ns1.domainnamedns.com and ns2.domainnamedns.com. Reputation data shows the domain is listed on a single security blocklist and is explicitly blocked by the PhishDestroy filtering service. VirusTotal has evaluated the domain, with 14 of 91 constituent security vendors marking it as malicious, reinforcing its classification as a generic phishing site. No additional intelligence such as page title, SSL certificate details, or hosting IP address has been disclosed, leaving the underlying infrastructure and target brand unspecified. The limited visibility of the hosting environment prevents attribution of the underlying autonomous system or geographic location. Defenders should continue to block sun3322.com at perimeter defenses, enforce DNS sinkholing where possible, and update endpoint security signatures to incorporate the observed detection pattern. Monitoring of future passive DNS records and any emergence of additional detections on threat intelligence platforms is recommended to capture potential changes in the domain’s operational posture. Given the active status, the presence on a blocklist, and the multi‑vendor detection count, the domain presents a high risk to users who may encounter phishing attempts originating from it. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 519c3f9e87615bbe85f187ebca358d3d TLS cert SHA-256: 02d0e6a9280b346b0293f82abfa965aa51a5a3d75b5d2ccf33ffd89525441871 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/sun3322.com/ JSON API: https://api.destroy.tools/v1/check?domain=sun3322.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 193,646 domains (83,086 alive under monitoring, 108,147 confirmed takedowns/dead). Site: https://phishdestroy.io