# PhishDestroy threat dossier — t79k.top ================================================================ Fetched: 2026-07-28 21:28:02 UTC Canonical: https://phishdestroy.io/domain/t79k.top/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 61/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai AlienVault OTX: 4 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 103.244.148.114 (HK, Hong Kong) ASN: AS135357 HONG KONG KOWLOON TELECOMMUNICATIONS CO.,LIMITED Hosting org: Shenzhenshihong Technology Development Co., Ltd Registrar: NameMart Pte. Ltd. Nameservers: ["ns1.1111343.com.", "ns2.1111343.com.", "ns3.1111343.com.", "ns4.1111343.com."] Page title: Welcome HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-10-09 Status: INVALID chain Fingerprint: 492ba05e7829aa884acaf223f15dd4a081585bce8e8b2a5b26a548dd6f77f442 Subject Alternative Names (related infrastructure — often same operator): - b42l.top - b42m.top - b47u.vip - b47v.vip - b47w.vip - f39m.top - f39n.top - g23v.top - g25n.top - g25o.top - g25p.top - g25t.top - g25u.top - h33g.top - h33i.top ... +84 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-28 15:03:09 UTC (by PhishDestroy tracker) Last verified: 2026-07-28 21:04:11 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 15:04:31 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] t79k.top Safety Check — Phishing Detected Analysis of t79k.top as of July 28, 2026 indicates that the domain remains active and serves a generic phishing campaign. The domain resolves to four authoritative name servers – ns1.1111343.com., ns2.1111343.com., ns3.1111343.com., and ns4.1111343.com. All four are hosted under the same parent domain, a pattern frequently observed in malicious infrastructure that relies on rapid DNS reconfiguration. The registrar listed for the domain is NameMart Pte. Ltd., a provider that has been associated with a number of abuse reports in the past, though no direct attribution to the current activity is confirmed. The site returns an HTTP 200 response, confirming that a web server is actively delivering content. VirusTotal analysis shows that one out of ninety‑one scanned security vendors flagged the domain, demonstrating that at least one detection engine recognized malicious behavior. Additionally, the domain appears on a single external blocklist and is explicitly blocked by the PhishDestroy service, reinforcing the perception of phishing intent. Despite these indicators, the limited number of detections and the single blocklist entry suggest that broader visibility may be constrained, possibly due to recent deployment or evasion techniques. No further intelligence such as SSL certificate details, page title, or associated brand targets has been disclosed, leaving the exact phishing lure undefined. Defenders should treat t79k.top as high‑risk. Recommended actions include adding the domain to local deny lists, monitoring DNS queries for the four listed name servers, and enforcing web‑filter policies that block HTTP traffic to the host. Continuous re‑scanning on VirusTotal or similar platforms is advised to capture any escalation in detection counts. Organizations employing email security gateways should ensure that any links to t79k.top are quarantined or rejected, and incident response teams should be prepared to investigate any user reports that reference this domain. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: 492ba05e7829aa884acaf223f15dd4a081585bce8e8b2a5b26a548dd6f77f442 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/t79k.top/ JSON API: https://api.destroy.tools/v1/check?domain=t79k.top Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 208,135 domains (82,977 alive under monitoring, 124,126 confirmed takedowns/dead). Site: https://phishdestroy.io