# PhishDestroy threat dossier — vavadansxt.com ================================================================ Fetched: 2026-07-29 16:17:31 UTC Canonical: https://phishdestroy.io/domain/vavadansxt.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 98/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 85.121.149.94 (MD, Chisinau) ASN: AS200019 ALEXHOST SRL Hosting org: Alexhost SRL Registrar: Fewmoretaps OU d/b/a Trustname.com !!! REGISTRAR INTEGRITY ALERT — Trustname / Fewmoretaps OU !!! Trustname (IANA #4318) is a shell company declaring EUR 120 annual revenue, 1 employee, negative equity, Belarusian ownership. Explicitly advertises itself as 'bulletproof' in its DNS TXT records. Primary source: https://phishdestroy.io/trustname-bulletproof-exposed Nameservers: eugene.ns.cloudflare.com, faye.ns.cloudflare.com Registered: 2026-07-23 Expires: 2027-07-23 Page title: Games - VAVADA Online HTTP response: 302 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-10-21 Status: INVALID chain Fingerprint: 2c316a0f12b1f4d7283ee1c4e9b5a6d3f7fa34049cc274246b6f7b7c16427804 Subject Alternative Names (related infrastructure — often same operator): - www.vavadansxt.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-23 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-28 20:41:59 UTC (by PhishDestroy tracker) Last verified: 2026-07-29 16:20:22 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019faa30-8b38-70c3-b461-7430aab3cdee/ Wayback Machine: https://web.archive.org/web/*/vavadansxt.com crt.sh CT logs: https://crt.sh/?q=%25.vavadansxt.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=vavadansxt.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/vavadansxt.com URLhaus: https://urlhaus.abuse.ch/host/vavadansxt.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 20:42:40 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] vavadansxt.com — Phishing Domain Under Investigation Report This report documents the ongoing investigation into vavadansxt.com, a domain associated with generic phishing threat indicators as of July 28, 2026. The domain was registered on July 23, 2026, through Fewmoretaps OU d/b/a Trustname.com and remains active. DNS records show the domain resolves to IP address 85.121.149.94 and is served via Cloudflare nameservers (eugene.ns.cloudflare.com and faye.ns.cloudflare.com). Currently, the domain is flagged on a single security blocklist, specifically by PhishDestroy. While the domain has been scanned by 91 vendors on VirusTotal, with none currently raising alerts, this absence of detections does not confirm that the domain is benign. There are no further blocklists, Safe Browsing warnings, OTX entries, HTTP status, or SSL certificate details noted in the available intelligence. There is no information on the site's actual content, as page title, scam kit details, or targeted brand are not present in the current dataset. The observable infrastructure and recent creation date may warrant caution, especially since the domain is under active investigation due to its presence on a phishing-specific blocklist. Defenders should continue monitoring for changes in detection coverage and further intelligence from threat feeds. Until additional technical evidence is gathered, network administrators are advised to treat vavadansxt.com as potentially hostile, restrict access, and update security controls accordingly. Investigation should remain open pending further analysis of web content and emerging threat intel. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: ff6ef3a968017259399de45ecdbf0bb5 TLS cert SHA-256: 2c316a0f12b1f4d7283ee1c4e9b5a6d3f7fa34049cc274246b6f7b7c16427804 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/vavadansxt.com/ JSON API: https://api.destroy.tools/v1/check?domain=vavadansxt.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,485 domains (83,252 alive under monitoring, 109,716 confirmed takedowns/dead). Site: https://phishdestroy.io