# PhishDestroy threat dossier — truemeet.buzz ================================================================ Fetched: 2026-07-28 13:31:12 UTC Canonical: https://phishdestroy.io/domain/truemeet.buzz/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 5/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Forcepoint ThreatSeeker, Gridinsoft, LevelBlue, SOCRadar Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 148.113.8.42 (IN, Mumbai) ASN: AS16276 OVH SAS Hosting org: OVHTECH R&D (INDIA) PRIVATE LIMITED Registrar: OwnRegistrar, Inc. Nameservers: ["ns2.xhost.co.in", "ns4.xhost.co.in"] Page title: Domain Registered — Action Required HTTP response: 301 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-09-22 Status: INVALID chain Fingerprint: 4e70f9b68cd055303b6c945ed93b220bc9465bbeba27fdd24566ef34cdfdb5f7 Subject Alternative Names (related infrastructure — often same operator): - host3.xhost.co.in ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-19 12:38:04 UTC (by PhishDestroy tracker) Last verified: 2026-07-28 12:44:45 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-20 01:44:32 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is truemeet.buzz a Phishing Site? Analysis of truemeet.buzz as of July 19, 2026 indicates the domain is actively hosting a generic phishing infrastructure. The site returns an HTTP 301 status and presents the page title "Domain Registered — Action Required," suggesting a registration‑related lure. DNS resolution points to IP 148.113.8.42, which is registered to OVHTECH R&D (INDIA) PRIVATE LIMITED, confirming the server’s geographic location in India. The domain is delegated to the nameservers ns2.xhost.co.in and ns4.xhost.co.in and is registered through OwnRegistrar, Inc. TLS is provided by a Let’s Encrypt certificate (YR2). Threat intelligence sources have placed truemeet.buzz on three security blocklists, and it is explicitly blocked by PhishDestroy, MetaMask, and SEAL. VirusTotal scans show five of ninety‑one security vendors flagging the domain, reinforcing the suspicion of malicious use. While the exact phishing payload or targeted brand is not disclosed, the available evidence confirms a high‑risk, active phishing operation. Defenders should immediately block traffic to truemeet.buzz at perimeter and endpoint layers, add the domain to internal deny‑lists, and continue monitoring for related C2 indicators tied to the resolved IP and nameserver infrastructure. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: 4e70f9b68cd055303b6c945ed93b220bc9465bbeba27fdd24566ef34cdfdb5f7 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/truemeet.buzz/ JSON API: https://api.destroy.tools/v1/check?domain=truemeet.buzz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 210,953 domains (85,393 alive under monitoring, 124,530 confirmed takedowns/dead). Site: https://phishdestroy.io