# PhishDestroy threat dossier — tokenbocket.top ================================================================ Fetched: 2026-07-29 09:01:02 UTC Canonical: https://phishdestroy.io/domain/tokenbocket.top/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 15/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, Bfore.Ai PreCrime, BitDefender, CRDF, CyRadar, ESET, Forcepoint ThreatSeeker, G-Data, Gridinsoft, Kaspersky, Lionic, Sophos, VIPRE, Webroot AlienVault OTX: 28 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 37.1.220.158 (NL, Meppel) ASN: AS58061 Scalaxy B.V. Hosting org: ISPIRIA Networks Ltd Registrar: Dominet (HK) Limited Nameservers: ["ns7.alidns.com.", "ns8.alidns.com."] Page title: tokenbocket.top HTTP response: 301 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: MyOrg / localhost Expires: 2026-10-22 Status: INVALID chain Fingerprint: 36fe8f7d39bdf6388cbeb96f2b0ca17a0022608e3784854690b4ede7f221aad5 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-28 17:43:10 UTC (by PhishDestroy tracker) Last verified: 2026-07-29 09:34:09 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 17:44:33 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] tokenbocket.top: Confirmed Phishing Site Analysis of tokenbocket.top indicates that the domain is actively being used for malicious phishing operations. The site returns an HTTP 301 status, suggesting a permanent redirect to another location, a technique commonly employed to evade simple URL filters. The domain is listed on a single security blocklist and has been explicitly blocked by the PhishDestroy feed, reinforcing its classification as a phishing vector. Infrastructure details show the domain is serviced by the Alibaba Cloud DNS nameservers ns7.alidns.com. and ns8.alidns.com., a pattern often observed in malicious campaigns that leverage inexpensive or disposable hosting. Registration records reveal the domain was purchased through Dominet (HK) Limited, a registrar based in Hong Kong, providing limited accountability and further supporting the low‑cost, disposable nature of the infrastructure. VirusTotal scans have returned 15 positive detections out of 91 security vendors, indicating that a notable minority of AV engines have identified the domain as malicious. The risk rating assigned to tokenbocket.top is high, consistent with its active status and the presence of multiple detections. No additional metadata such as SSL certificate details, page title, or targeted brand information is available in the current intelligence set, leaving the exact phishing lure and victim profile uncertain. Defenders should prioritize immediate network‑level blocking of tokenbocket.top across firewalls, proxy servers, and DNS filtering solutions. Continuous monitoring of DNS query logs for the domain and its associated nameservers is advised to detect potential lateral movement or related campaign infrastructure. Organizations using threat‑intelligence feeds should ensure the domain is ingested from the PhishDestroy and VirusTotal sources to maintain up‑to‑date protection. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: 36fe8f7d39bdf6388cbeb96f2b0ca17a0022608e3784854690b4ede7f221aad5 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/tokenbocket.top/ JSON API: https://api.destroy.tools/v1/check?domain=tokenbocket.top Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 194,182 domains (83,156 alive under monitoring, 108,406 confirmed takedowns/dead). Site: https://phishdestroy.io