# tallyphase2.xyz — SUSPICIOUS > Caution advised with tallyphase2.xyz. This domain exhibits phishing traits and is currently under investigation. Avoid interaction until cleared. ## Summary PhishDestroy identifies tallyphase2.xyz as a generic phishing candidate. The domain was created recently on February 28, 2026, and is currently classified as under_investigation due to suspicious activity patterns. Technical indicators show tallyphase2.xyz resolves to IP 188.114.96.3 and is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED. VirusTotal currently shows zero detections, indicating no vendor flags yet, but other factors suggest caution. The domain's status remains active and under continuous monitoring by PhishDestroy. Users are advised to avoid engaging with tallyphase2.xyz until further analysis confirms its safety. ## Threat Details - Verdict: SUSPICIOUS - Site status: alive (HTTP 530) - Page title: idOS Token Sale – Phase 2 Open Round ## Domain Intelligence - Registered: 2026-03-06 15:07:01 - Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED - Country: HK - IP: 188.114.96.3 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: amanda.ns.cloudflare.com armando.ns.cloudflare.com - SSL Issuer: none ## Detection Status - VirusTotal: 1 vendors flagged Vendors: ["Fortinet"] - Google Safe Browsing: clean - Blocklists: 3 hits Lists: ["PhishDestroy", "MetaMask", "SEAL"] ## Evidence - Screenshot: https://i.ibb.co/kg10m6sV/e9b70d04dccb.png - Cloudflare Radar: https://radar.cloudflare.com/domains/tallyphase2.xyz - PhishDestroy: https://phishdestroy.io/domain/tallyphase2.xyz/ - LLM endpoint: https://phishdestroy.io/domain/tallyphase2.xyz/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/tallyphase2.xyz/ Last updated: 2026-03-16