# PhishDestroy threat dossier — trsrylab.info ================================================================ Fetched: 2026-08-01 13:24:21 UTC Canonical: https://phishdestroy.io/domain/trsrylab.info/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 98/100 (PhishDestroy scoring — see methodology below) Scam classification: Fake Airdrop ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 5/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Fortinet, Gridinsoft, LevelBlue, SOCRadar Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.67.141.31 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED !!! REGISTRAR INTEGRITY ALERT — NiceNIC !!! NiceNIC International: over 90% of its registered domains are associated with illegal content; documented systematic abuse-report non-response. Primary sources: https://phishdestroy.io/nicenic-real https://phishdestroy.io/nicenic-verdict Nameservers: igor.ns.cloudflare.com, katelyn.ns.cloudflare.com Registered: 2026-07-25 Expires: 2027-07-25 Page title: TRSRY Allocation Live — Claim Your $TRSRY Tokens HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-10-23 Status: INVALID chain Fingerprint: 44f5fe01da892810c2d01313729782c8ae8002092bdb10eaeb9273d25e37613f ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-25 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-28 19:49:32 UTC (by PhishDestroy tracker) First reported: 2026-07-28 18:05:19 UTC (abuse notice filed) Last verified: 2026-08-01 12:56:56 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa9da-3d1f-76d1-a598-31eb36152b59/ URLQuery: https://urlquery.net/report/02c5a304-b573-448c-b73c-33ab7d4647d9 Wayback Machine: https://web.archive.org/web/*/trsrylab.info crt.sh CT logs: https://crt.sh/?q=%25.trsrylab.info Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=trsrylab.info AlienVault OTX: https://otx.alienvault.com/indicator/domain/trsrylab.info URLhaus: https://urlhaus.abuse.ch/host/trsrylab.info/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 19:50:33 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] trsrylab.info used in generic phishing campaign Analysis of trsrylab.info shows a domain registered on July 25 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and currently resolved to the Cloudflare‑hosted address 172.67.141.31. The authoritative name servers igor.ns.cloudflare.com and katelyn.ns.cloudflare.com are consistent with a typical Cloudflare front‑end, providing anonymity of the underlying hosting infrastructure. VirusTotal records indicate that the domain has been scanned by 91 security vendors, none of which have raised a detection at the time of the scan. The domain appears on a single external blocklist, PhishDestroy, which has already classified it as malicious and contributed to its current blocked status. No additional public data such as SSL certificate details, HTTP response codes, page title, or Safe Browsing verdicts are presently available, leaving the content of the site unverified. Given the recent registration date, the presence on a phishing‑focused blocklist, and the lack of visible defensive signals, the domain should be considered a high‑confidence indicator of a generic phishing campaign. Defenders are advised to immediately add trsrylab.info to network‑level deny lists, update proxy and DNS filtering rules, and monitor outbound connections to the associated IP address for anomalous activity. Continuous re‑evaluation is recommended as additional telemetry becomes available, particularly regarding payload delivery, credential‑stealing pages, or association with other malicious infrastructure. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260728-58790D Favicon MD5: 9f504444f85a5af2eef9264b02ae40be TLS cert SHA-256: 44f5fe01da892810c2d01313729782c8ae8002092bdb10eaeb9273d25e37613f ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/trsrylab.info/ JSON API: https://api.destroy.tools/v1/check?domain=trsrylab.info Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,858 domains (90,613 alive under monitoring, 27,318 confirmed neutralized). Site: https://phishdestroy.io