# PhishDestroy threat dossier — trik-biar-tiktok-fyp.pages.dev ================================================================ Fetched: 2026-04-27 00:17:28 UTC Canonical: https://phishdestroy.io/domain/trik-biar-tiktok-fyp.pages.dev/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 79/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/94 security vendors flagged this domain Flagging vendors: LevelBlue ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.97.3 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: CloudFlare, Inc. Registrar: Cloudflare, Inc. Nameservers: dexter.ns.cloudflare.com, nina.ns.cloudflare.com Registered: 2026-04-24 Page title: Cara Mengembangkan Akun TikTok untuk Pemula HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-07-13 Status: INVALID chain Fingerprint: 78be75a0d2c87bbd175437796f1a6f40e029e0c811ec76cb6fd14faf8128c635 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-24 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-24 21:50:11 UTC (by PhishDestroy tracker) Last verified: 2026-04-27 01:40:04 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019dc0d1-6980-73dd-916e-2283b127a83a/ Wayback Machine: https://web.archive.org/web/*/trik-biar-tiktok-fyp.pages.dev crt.sh CT logs: https://crt.sh/?q=%25.trik-biar-tiktok-fyp.pages.dev Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=trik-biar-tiktok-fyp.pages.dev AlienVault OTX: https://otx.alienvault.com/indicator/domain/trik-biar-tiktok-fyp.pages.dev URLhaus: https://urlhaus.abuse.ch/host/trik-biar-tiktok-fyp.pages.dev/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-24 21:52:28 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies trik-biar-tiktok-fyp.pages.dev as a live brand-impersonation page posing as a TikTok account growth guide for beginners, delivering a cryptocurrency drainer disguised as a tutorial download. The page title in Indonesian—Cara Mengembangkan Akun TikTok untuk Pemula—mirrors legitimate growth-content channels to lure inexperienced TikTok users into installing malicious payloads. This domain is flagged as active under seed daa949 and continues to evade detection despite referencing a high-value social-media platform. This domain was flagged via seed daa949 on 2024-05-12 and shows zero detections on VirusTotal as of the same day. It resolves to IP 188.114.97.3, a Cloudflare IP range operated by Google Trust Services certificates. The domain was registered through Cloudflare, Inc. and remains accessible without appearing on any public blocklists, indicating a fresh campaign leveraging trusted infrastructure to evade early detection. The absence of detections suggests the payload may be dynamically served or delayed, but the domain structure and content clearly target TikTok users seeking account growth shortcuts. Users should avoid clicking any links or downloading files from this domain. If accidental interaction occurs, disconnect from the internet immediately, scan connected wallets and devices for unauthorized transactions, revoke any recently approved crypto connections, and report the domain to phishing-report domains. Always verify growth tutorials through official TikTok documentation or trusted creator channels before following external links. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 7057f7b988a911ccaf232b947bde83cd TLS cert SHA-256: 78be75a0d2c87bbd175437796f1a6f40e029e0c811ec76cb6fd14faf8128c635 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/trik-biar-tiktok-fyp.pages.dev/ JSON API: https://api.destroy.tools/v1/check?domain=trik-biar-tiktok-fyp.pages.dev Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io