# PhishDestroy threat dossier — v0808.fun ================================================================ Fetched: 2026-05-01 20:13:01 UTC Canonical: https://phishdestroy.io/domain/v0808.fun/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users (type: status_split) (score: 1/6) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/94 security vendors flagged this domain Flagging vendors: Gridinsoft, LevelBlue ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 154.23.186.124 (HK, Hong Kong) ASN: AS140227 Hong Kong Communications International Co., Limited Hosting org: Hong Kong Communications International Co., Limited Registrar: Gname.com Pte. Ltd. Nameservers: n1.xundns.com, n2.xundns.com Registered: 2026-04-25 Page title: 美团视频 HTTP response: 403 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R13 Expires: 2026-07-22 Status: INVALID chain Fingerprint: 6708c3ccc460071a1a17350e954683329e610938ebbd56f6c37e388d1977e497 Subject Alternative Names (related infrastructure — often same operator): - 08080.fun - 08080.tv - 08808.icu - 08808.top - 08808.xyz - 18080.icu - 18080.xyz - 18808.xyz - 28080.xyz - 28808.xyz - 48808.xyz - 58808.xyz - 68808.icu - 78808.icu - 78808.top ... +19 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-25 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-25 08:17:37 UTC (by PhishDestroy tracker) Last verified: 2026-05-01 21:05:45 UTC Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019dc30f-2e4f-715c-83ae-80151ea88e81/ Wayback Machine: https://web.archive.org/web/*/v0808.fun crt.sh CT logs: https://crt.sh/?q=%25.v0808.fun Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=v0808.fun AlienVault OTX: https://otx.alienvault.com/indicator/domain/v0808.fun URLhaus: https://urlhaus.abuse.ch/host/v0808.fun/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-25 08:18:26 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies v0808.fun as a live crypto drainer phishing domain actively deployed in the wild. This domain is categorized under generic_phishing with an under_investigation risk level and remains active as of the latest scan. The threat involves a malicious crypto drainer designed to exfiltrate cryptocurrency assets from unsuspecting users, leveraging deceptive tactics to appear legitimate. No specific brand impersonation has been confirmed at this stage, but the domain's infrastructure is consistent with high-risk phishing operations targeting digital asset holders. This domain was flagged by 0 of 95 VirusTotal vendors as of the most recent analysis, indicating a lack of immediate detection by automated scanning tools. The domain is registered through Gname.com Pte. Ltd., resolves to the IP address 154.23.186.124, and was created on April 23, 2026. The SSL certificate is issued by Let's Encrypt, which does not inherently validate the domain's safety. Additionally, the domain is not currently listed on any known blocklists, and its trust scores remain unverified due to its recent creation and low detection rates. These factors contribute to its elevated risk profile despite the absence of immediate automated detections. Given the active status of v0808.fun and its classification as a crypto drainer, users are strongly advised to avoid interacting with this domain under any circumstances. The lack of detections by VirusTotal vendors suggests that traditional security tools may not yet recognize this threat, increasing the risk of successful exploitation. PhishDestroy recommends verifying the safety of any suspicious domains through its platform and reporting such incidents to enhance collective threat intelligence. Users who may have already engaged with this domain should immediately transfer their remaining assets to a secure wallet and conduct a full security audit of their cryptocurrency holdings. Additionally, consider revoking any permissions granted to addresses or smart contracts associated with this domain to mitigate potential losses. [Updates since narrative was generated:] - VirusTotal detections: now 2/94 (narrative was written when count was lower) ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 289ca844f56028a166ec70167eb7ec1d TLS cert SHA-256: 6708c3ccc460071a1a17350e954683329e610938ebbd56f6c37e388d1977e497 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/v0808.fun/ JSON API: https://api.destroy.tools/v1/check?domain=v0808.fun Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io