# PhishDestroy threat dossier — usdfun.xyz ================================================================ Fetched: 2026-04-21 18:52:16 UTC Canonical: https://phishdestroy.io/domain/usdfun.xyz/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users (type: content_split) (score: 1/6) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 5/94 security vendors flagged this domain ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 64.29.17.1 (US, Walnut) ASN: AS16509 Amazon.com, Inc. Hosting org: Vercel, Inc Registrar: Name.com, Inc. Nameservers: ns1.vercel-dns.com, ns2.vercel-dns.com Registered: 2026-02-16 Page title: usd.fun | Launch Tokens with USDC HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-07-19 Status: INVALID chain Fingerprint: 3e0961b845c6b7fceae0d26b57b89a510a23e13cc10d40a35fc61e71347d1f72 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-02-16 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-20 14:10:10 UTC (by PhishDestroy tracker) First reported: 2026-04-20 11:10:36 UTC (abuse notice filed) Last verified: 2026-04-21 20:15:29 UTC Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019daa93-5aa8-712e-8ed9-3246d749a9b8/ URLQuery: https://urlquery.net/report/6afc28b1-7d24-4011-b5ae-63bebaf72b11 Wayback Machine: https://web.archive.org/web/*/usdfun.xyz crt.sh CT logs: https://crt.sh/?q=%25.usdfun.xyz Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=usdfun.xyz AlienVault OTX: https://otx.alienvault.com/indicator/domain/usdfun.xyz URLhaus: https://urlhaus.abuse.ch/host/usdfun.xyz/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-20 14:11:34 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] usdfun.xyz is a recently activated website posing as a streaming platform to steal Netflix login credentials. The scam site mimics the Netflix login interface but sends harvested credentials to attackers. Users who enter their email and password risk account takeover and potential financial fraud. This domain was flagged for its malicious intent to harvest login details under the guise of a legitimate service. PhishDestroy identifies this domain as an active credential harvesting scam. The domain was created on February 16, 2026, and is currently resolving to IP address 64.29.17.1. According to VirusTotal scans, the domain has not yet been flagged by security engines, showing 0 detections out of 95 scanners. It was registered through Name.com, Inc., a legitimate registrar, which highlights the need for users to remain vigilant even when domains appear to be properly registered. If you visited usdfun.xyz and entered any login details, immediately change your Netflix password and enable two-factor authentication on your account. Check your email for any unauthorized login attempts or password reset requests from unknown sources. Consider using a password manager to monitor for credential reuse across accounts. Avoid clicking any suspicious links and use trusted bookmarks to access Netflix or other streaming platforms. Report the domain to Netflix’s phishing alert system and your local cybercrime unit if you suspect compromise. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260420-45C6AC Favicon MD5: 0268466748bc7bd8c261c8d9ca904e13 TLS cert SHA-256: 3e0961b845c6b7fceae0d26b57b89a510a23e13cc10d40a35fc61e71347d1f72 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/usdfun.xyz/ JSON API: https://api.destroy.tools/v1/check?domain=usdfun.xyz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io