# PhishDestroy threat dossier — tr.padisahbet-giris2026.org ================================================================ Fetched: 2026-05-08 16:55:20 UTC Canonical: https://phishdestroy.io/domain/tr.padisahbet-giris2026.org/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 7/95 security vendors flagged this domain Flagging vendors: BitDefender, Forcepoint ThreatSeeker, G-Data, Gridinsoft, Kaspersky, OpenPhish, Sophos Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 104.21.22.105 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: Squarespace Domains LLC Nameservers: damon.ns.cloudflare.com, itzel.ns.cloudflare.com Registered: 2026-05-07 Page title: Padişahbet - Padişahbet Giriş Adresi - Padişahbet Güncel Giriş 2026 HTTP response: 521 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E8 Expires: 2026-08-05 Status: INVALID chain Fingerprint: 81a0f3aa4d0f439c95e7d2b0b4e4cb15435b04a2a87b75053b1ccba511f5f98d Subject Alternative Names (related infrastructure — often same operator): - padisahbet-giris2026.org ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-07 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-08 17:16:05 UTC (by PhishDestroy tracker) Last verified: 2026-05-08 19:50:04 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e07f0-30d3-72df-a3b1-218d027b2f2e/ Wayback Machine: https://web.archive.org/web/*/tr.padisahbet-giris2026.org crt.sh CT logs: https://crt.sh/?q=%25.tr.padisahbet-giris2026.org Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=tr.padisahbet-giris2026.org AlienVault OTX: https://otx.alienvault.com/indicator/domain/tr.padisahbet-giris2026.org URLhaus: https://urlhaus.abuse.ch/host/tr.padisahbet-giris2026.org/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-08 17:17:05 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] tr.padisahbet-giris2026.org is an active crypto drainer domain impersonating a gaming platform, posing an elevated risk to cryptocurrency users. This site was designed to trick visitors into connecting wallets and draining funds under the guise of a legitimate Turkish betting service ('padisahbet-giris2026'). The threat actor leverages spoofed branding and urgency to harvest private keys and authorize malicious transactions. Security researchers and users should treat this domain with extreme caution and avoid all interactions involving wallet connections or fund transfers. This domain was flagged by PhishDestroy and confirmed through multiple intelligence sources. It resolves to IP 104.21.22.105, uses a Let’s Encrypt SSL certificate, and was registered on May 07, 2026 through Squarespace Domains LLC. VirusTotal reports 7 out of 95 security vendors detecting malicious activity. The domain is currently blocked by OpenPhish and appears on one public blocklist, indicating confirmed malicious reputation. Despite using a reputable registrar and a valid SSL certificate, these factors do not mitigate the active crypto drainer threat. Users should immediately block tr.padisahbet-giris2026.org at the network and DNS level. Never connect a cryptocurrency wallet or enter credentials on this site. If funds were drained, report the incident to local law enforcement and your wallet provider. Share indicators of compromise with threat intelligence platforms. Organizations should deploy endpoint protection to detect wallet-draining scripts and block this domain via firewall rules or DNS filtering services. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 0f334a4b7e5b75654583f6260faf83b7 TLS cert SHA-256: 81a0f3aa4d0f439c95e7d2b0b4e4cb15435b04a2a87b75053b1ccba511f5f98d ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/tr.padisahbet-giris2026.org/ JSON API: https://api.destroy.tools/v1/check?domain=tr.padisahbet-giris2026.org Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 147,310 domains (48,258 alive under monitoring, 98,768 confirmed takedowns/dead). Site: https://phishdestroy.io