# PhishDestroy threat dossier — syraikxak.xyz ================================================================ Fetched: 2026-07-29 18:53:36 UTC Canonical: https://phishdestroy.io/domain/syraikxak.xyz/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 6/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Fortinet, SOCRadar AlienVault OTX: 4 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 103.224.182.215 (US, San Diego) ASN: AS133618 Trellian Pty. Limited Hosting org: Trellian Pty. Limited Registrar: Dynadot Inc Nameservers: ["ns15.abovedomains.com", "ns16.abovedomains.com"] Page title: ww38.syraikxak.xyz HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-10-06 Status: INVALID chain Fingerprint: 013ba17dc0688e4c458724487d99a23a6d546903c369cff9449a26aa9263fc00 Subject Alternative Names (related infrastructure — often same operator): - canyonmusic.studio - contrary.it - cpen.live - definitions23.co.uk - demon45.bet - educationwala.info - electroniquepratique.com - employmentandthelaw.com - generamedicine.co - iamascammer.com - internetaccess.com.au - majority.org - matrixprimecapital.com - new-houses.com - nyuhr.org ... +9 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-28 15:03:09 UTC (by PhishDestroy tracker) Last verified: 2026-07-29 16:20:23 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 15:04:13 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is syraikxak.xyz a Phishing Scam? Analysis as of July 28, 2026 indicates that the domain syraikxak.xyz is actively serving content over HTTP with a status code of 200. The domain is registered through Dynadot Inc and uses the authoritative name servers ns15.abovedomains.com and ns16.abovedomains.com. Threat intelligence categorizes the site as a generic phishing operation, and the domain is currently listed on one security blocklist. It has been intercepted by the PhishDestroy mitigation service, confirming that known phishing filters are actively blocking it. VirusTotal scans show that six out of ninety‑one antivirus and URL‑reputation engines have flagged the domain as malicious, providing additional corroboration of its malicious intent. No publicly available TLS certificate information, IP address attribution, or page title has been released, limiting deeper infrastructure profiling. The lack of SSL data prevents verification of certificate misuse, and the absence of a disclosed landing‑page title means the specific impersonated brand or credential‑capture template cannot be confirmed at this stage. Defenders should add syraikxak.xyz to outbound and inbound deny lists across firewalls, DNS resolvers, and proxy devices. Given the active blocklist entry and the PhishDestroy block, organizations relying on those services already have a layer of protection, but supplemental local filtering is advised. Continuous monitoring of the domain’s DNS records and any changes in the detection count on VirusTotal is recommended, as well as periodic re‑scans to capture any new payloads or delivery methods. In summary, the available evidence—active HTTP response, registrar data, name‑server configuration, blocklist presence, PhishDestroy interception, and multi‑vendor detections—supports a high‑risk rating for syraikxak.xyz. Until additional infrastructure details become available, the domain should be treated as hostile and blocked. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: 013ba17dc0688e4c458724487d99a23a6d546903c369cff9449a26aa9263fc00 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/syraikxak.xyz/ JSON API: https://api.destroy.tools/v1/check?domain=syraikxak.xyz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,500 domains (83,267 alive under monitoring, 109,716 confirmed takedowns/dead). Site: https://phishdestroy.io