# PhishDestroy threat dossier — synbeauty.by ================================================================ Fetched: 2026-07-31 04:40:04 UTC Canonical: https://phishdestroy.io/domain/synbeauty.by/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Credential Phishing ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain Flagging vendors: SOCRadar AlienVault OTX: 1 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 45.155.60.8 (BY, Minsk) ASN: AS57724 DDOS-GUARD LTD Hosting org: Tilda Publishing JSC Registrar: Reliable Software, Ltd Nameservers: u1.hoster.by, u2.hoster.by Registered: 2020-02-12 Expires: 2027-02-12 Page title: 403 HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R13 Expires: 2026-08-21 Status: INVALID chain Fingerprint: d8262cb43a6d4087fc2b3e55612bd06d1d1d85f2396bb58d3245b236f82e2be2 Subject Alternative Names (related infrastructure — often same operator): - www.synbeauty.by ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2020-02-12 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-17 11:10:50 UTC (by PhishDestroy tracker) Last verified: 2026-07-31 04:20:35 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f6f55-efe0-703c-8fa2-bbb371758085/ Wayback Machine: https://web.archive.org/web/*/synbeauty.by crt.sh CT logs: https://crt.sh/?q=%25.synbeauty.by Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=synbeauty.by AlienVault OTX: https://otx.alienvault.com/indicator/domain/synbeauty.by URLhaus: https://urlhaus.abuse.ch/host/synbeauty.by/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-17 11:20:21 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Synbeauty.by phishing site harvesting user credentials Analysis indicates that the domain synbeauty.by is currently active and has been observed resolving to the IPv4 address 45.155.60.8. The domain was registered on 12 February 2020 through the registrar Reliable Software, Ltd and is hosted on the name‑server pair u1.hoster.by and u2.hoster.by. The registration date and the continued operation of the domain suggest a persistent infrastructure that could be leveraged for credential‑stealing campaigns, consistent with its classification as a generic_phishing site. No public content has been captured, and the exact phishing template or targeted brand has not been disclosed, leaving the specific attack vector uncertain. The presence of a dedicated registrar and stable DNS configuration implies that the operators have maintained control for several years, which may facilitate repeated abuse. Defenders should add 45.155.60.8 and synbeauty.by to block lists, monitor DNS queries for the domain and its name‑servers, and consider sinkholing the IP if feasible. Continuous telemetry collection is recommended to detect any future payload delivery or credential‑harvesting activity associated with this infrastructure. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: e0bb9471539215d2334d05d123566f0c TLS cert SHA-256: d8262cb43a6d4087fc2b3e55612bd06d1d1d85f2396bb58d3245b236f82e2be2 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/synbeauty.by/ JSON API: https://api.destroy.tools/v1/check?domain=synbeauty.by Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 196,188 domains (84,174 alive under monitoring, 27,089 confirmed neutralized). Site: https://phishdestroy.io