# PhishDestroy threat dossier — tristero-dex.com ================================================================ Fetched: 2026-07-30 17:54:32 UTC Canonical: https://phishdestroy.io/domain/tristero-dex.com/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 76/100 (PhishDestroy scoring — see methodology below) Scam classification: Fake Exchange ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 10/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET, G-Data, Gridinsoft, Kaspersky, SOCRadar, Sophos AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 186.2.175.109 (BZ, Belmopan) ASN: AS59692 IQWeb FZ-LLC Hosting org: Iqweb LLC Registrar: Fewmoretaps OU d/b/a Trustname.com !!! REGISTRAR INTEGRITY ALERT — Trustname / Fewmoretaps OU !!! Trustname (IANA #4318) is a shell company declaring EUR 120 annual revenue, 1 employee, negative equity, Belarusian ownership. Explicitly advertises itself as 'bulletproof' in its DNS TXT records. Primary source: https://phishdestroy.io/trustname-bulletproof-exposed Nameservers: ares.trustname.com, ns1.anycastdns.cz, ns2.anycastdns.cz, zeus.trustname.com Registered: 2026-07-24 Expires: 2027-07-24 Page title: Tristero DEX — #1 Decentralized Exchange | Swap, Bridge, Pool HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-10-22 Status: INVALID chain Fingerprint: 035a328bc0219b84f7d064a6b5a5751f1519b61dea074ed5841de39b37431043 Subject Alternative Names (related infrastructure — often same operator): - www.tristero-dex.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-24 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-28 20:36:57 UTC (by PhishDestroy tracker) First reported: 2026-07-28 18:59:19 UTC (abuse notice filed) Last verified: 2026-07-30 16:20:22 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019faa28-3f6e-7582-80b2-47b8d7c6d0c3/ URLQuery: https://urlquery.net/report/b670cf96-e566-4c4b-978b-bb7b5a25b9e1 Wayback Machine: https://web.archive.org/web/*/tristero-dex.com crt.sh CT logs: https://crt.sh/?q=%25.tristero-dex.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=tristero-dex.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/tristero-dex.com URLhaus: https://urlhaus.abuse.ch/host/tristero-dex.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 20:38:17 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] tristero-dex.com Fake Crypto Exchange Phishing Alert Analysis of tristero-dex.com indicates an active phishing domain targeting cryptocurrency exchange users, registered on July 24, 2026, through Fewmoretaps OU operating under Trustname.com. The domain resolves to IP address 186.2.175.109, which has not been widely flagged by security vendors at the time of this report. Infrastructure review shows the domain is currently listed on one security blocklist, specifically PhishDestroy, suggesting early detection of malicious intent. Nameserver configuration includes ares.trustname.com, ns1.anycastdns.cz, ns2.anycastdns.cz, and zeus.trustname.com, a pattern consistent with bulletproof or low-reputation hosting providers. VirusTotal scans from 91 vendors returned no detections as of July 28, 2026; however, this absence does not confirm safety, particularly given the domain's recent registration and single blocklist appearance. The domain remains active with no observable takedown or suspension, increasing the likelihood of ongoing phishing operations. Defenders are advised to treat this domain as high-risk for credential harvesting or wallet-draining attacks, particularly in crypto-related contexts. Monitoring should include DNS resolution changes, SSL certificate updates, and additional blocklist appearances. Given the lack of confirmed brand impersonation in available metadata, the exact exchange being mimicked is not yet determined, but the domain name suggests a focus on decentralized exchange (DEX) platforms. Organizations should implement real-time blocking of this domain and its associated IP, while awaiting further behavioral analysis or victim reports to clarify the attack vector. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260728-9B6EE7 Favicon MD5: f6bcbe4af2813b9351387122db90ecc0 TLS cert SHA-256: 035a328bc0219b84f7d064a6b5a5751f1519b61dea074ed5841de39b37431043 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/tristero-dex.com/ JSON API: https://api.destroy.tools/v1/check?domain=tristero-dex.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,949 domains (83,647 alive under monitoring, 110,042 confirmed takedowns/dead). Site: https://phishdestroy.io