# PhishDestroy threat dossier — syreenlabs.com ================================================================ Fetched: 2026-08-01 13:47:47 UTC Canonical: https://phishdestroy.io/domain/syreenlabs.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 97/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain Flagging vendors: Bfore.Ai PreCrime AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.97.3 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: CloudFlare, Inc. Registrar: Cloudflare, Inc. Nameservers: ["alexa.ns.cloudflare.com", "burt.ns.cloudflare.com"] Page title: Syreen Chain — Next-Gen Layer 1 Blockchain | EVM Compatible, MEV Protected, 500ms Blocks HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE1 Expires: 2026-10-10 Status: INVALID chain Fingerprint: 4645e765501db0a74c73923e043fab28fce2a2287f77da988f6ead27d079b28f ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-28 16:03:09 UTC (by PhishDestroy tracker) Last verified: 2026-08-01 12:54:14 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 16:05:31 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] SyreenLabs.com used in high‑risk generic phishing On July 28, 2026 the domain syreenlabs.com was identified as an active high‑risk generic phishing infrastructure. Registration data shows the domain was created through Cloudflare, Inc., and its authoritative name servers are alexa.ns.cloudflare.com and burt.ns.cloudflare.com, indicating the use of Cloudflare’s DNS services. An HTTP request to the root of the site returns a 200 OK status, confirming that a web server is currently responding. VirusTotal analysis records a single positive detection out of 91 scanned security vendors, demonstrating that at least one vendor has identified malicious behavior associated with the domain. The domain is presently listed on one public security blocklist and has been blocked by the PhishDestroy filtering service, providing additional evidence of its abusive use. No further public intelligence such as associated IP addresses, SSL certificate details, or page title information is available at this time. The limited visibility suggests that the campaign may be employing short‑lived hosting or dynamically changing endpoints, a tactic often observed in phishing operations seeking to evade static defenses. Defenders should continue to monitor syreenlabs.com for any changes in detection scores, add the domain to local blocklists, and enforce outbound filtering to prevent credential submission to the site. Network traffic to the domain’s name servers should be scrutinized, and any attempted connections to the domain should be terminated. Ongoing threat‑intel feeds should be consulted for updates, and incident response teams should be prepared to investigate any compromised accounts that reference syreenlabs.com. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: 4645e765501db0a74c73923e043fab28fce2a2287f77da988f6ead27d079b28f ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/syreenlabs.com/ JSON API: https://api.destroy.tools/v1/check?domain=syreenlabs.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,861 domains (90,616 alive under monitoring, 27,318 confirmed neutralized). Site: https://phishdestroy.io