# PhishDestroy threat dossier — u29q.top ================================================================ Fetched: 2026-07-30 13:49:04 UTC Canonical: https://phishdestroy.io/domain/u29q.top/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 7/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Fortinet, Gridinsoft, LevelBlue, SOCRadar AlienVault OTX: 4 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 103.244.148.113 (HK, Hong Kong) ASN: AS135357 HONG KONG KOWLOON TELECOMMUNICATIONS CO.,LIMITED Hosting org: Shenzhenshihong Technology Development Co., Ltd Registrar: NameMart Pte. Ltd. Nameservers: ["ns1.1111343.com.", "ns2.1111343.com.", "ns3.1111343.com.", "ns4.1111343.com."] Page title: u31w.top HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-10-21 Status: INVALID chain Fingerprint: 0308d7926e7fa58786ae2df81287c4b2d5025007c64de8a53183904d74464c9f Subject Alternative Names (related infrastructure — often same operator): - 100361.cc - 18038.xyz - 19566.xyz - 20398.xyz - 20401.xyz - 20403.xyz - 20417.xyz - 20420.xyz - 20445.xyz - 20457.xyz - 20469.xyz - 20518.xyz - 20522.xyz - 20533.xyz - 20538.xyz ... +84 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-28 18:33:08 UTC (by PhishDestroy tracker) Last verified: 2026-07-30 12:45:15 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 18:53:20 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is u29q.top Hosting a High-Risk Phishing Threat? Analysis of u29q.top as of July 28, 2026, indicates significant risk indicators consistent with active phishing operations. The domain currently responds with HTTP status 200, confirming it is online and accessible. It resolves to IP address 103.244.148.113 and is registered via NameMart Pte. Ltd. The infrastructure utilizes four nameservers under the 1111343.com domain, which may suggest use of a third-party DNS provider or potential involvement in bulk domain operations. Security intelligence reveals that u29q.top has been flagged by 5 of 91 vendors on VirusTotal, indicating that multiple independent threat detection engines have identified malicious or suspicious characteristics. The domain also appears on at least one security blocklist and has been specifically blocked by PhishDestroy, further corroborating its association with phishing activity. These findings are concrete threat indicators, though the specific lure, page content, or targeted brand are not yet analyzed or disclosed in available evidence. Defenders should treat u29q.top as a high-priority threat. The combination of active status, multi-vendor detections, blocklist inclusion, and explicit action by PhishDestroy justifies immediate blocking at both network and endpoint levels. Further investigation into associated infrastructure—such as the 103.244.148.113 IP and related domains using 1111343.com nameservers—is recommended to identify wider campaign activity. Since the exact page content and attack vectors are not yet confirmed, defenders should monitor for user access attempts and collect forensic artifacts if any traffic is observed. Ongoing threat intelligence updates should be consulted to track changes in status or new detection events. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: 0308d7926e7fa58786ae2df81287c4b2d5025007c64de8a53183904d74464c9f ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/u29q.top/ JSON API: https://api.destroy.tools/v1/check?domain=u29q.top Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,828 domains (83,526 alive under monitoring, 110,042 confirmed takedowns/dead). Site: https://phishdestroy.io