# PhishDestroy threat dossier — vgb-dex.live ================================================================ Fetched: 2026-06-07 03:27:13 UTC Canonical: https://phishdestroy.io/domain/vgb-dex.live/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: fake_dex Targeted brand: vagachain Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users (type: content_divergence) (score: 1/6) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 10/92 security vendors flagged this domain Public blocklists: listed on 4 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.96.3 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: CloudFlare, Inc. Registrar: Dynadot Inc Nameservers: kara.ns.cloudflare.com, rustam.ns.cloudflare.com Registered: 2026-05-01 Expires: 2027-05-01 Page title: VAGACHAIN | Open-Source Blockchain Protocol for Agent Economies HTTP response: 200 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-01 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-11 06:23:18 UTC (by PhishDestroy tracker) First reported: 2026-05-11 03:25:12 UTC (abuse notice filed) Last verified: 2026-06-02 17:20:40 UTC Neutralised: 2026-06-06 17:31:13 UTC Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e150d-9dec-70c1-b248-3a0b538245c1/ URLQuery: https://urlquery.net/report/54a6dcea-557d-4e4c-a20a-e0bd1813311d Wayback Machine: https://web.archive.org/web/*/vgb-dex.live crt.sh CT logs: https://crt.sh/?q=%25.vgb-dex.live Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=vgb-dex.live AlienVault OTX: https://otx.alienvault.com/indicator/domain/vgb-dex.live URLhaus: https://urlhaus.abuse.ch/host/vgb-dex.live/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-11 06:24:56 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies vgb-dex.live as a live generic phishing domain posing as the legitimate Vagachain blockchain protocol. The site’s page title, “VAGACHAIN | Open-Source Blockchain Protocol for Agent Economies,” is an exact copy of the real project’s branding, designed to trick visitors into connecting wallets or submitting private keys. Unlike legitimate blockchain gateways, this domain was registered on May 01, 2026 through Dynadot Inc and resolves to IP 188.114.96.3. Despite using a valid Let’s Encrypt SSL certificate, it currently shows zero detections on VirusTotal, indicating it has evaded automated scanning tools—making it especially dangerous for unsuspecting users. This domain was flagged due to its high-risk mimicry of a legitimate decentralized protocol. The mismatch between the professional-sounding title and the freshly registered domain (just days old) is a classic tactic used in crypto phishing. The attacker likely created this site to harvest login credentials, drain wallets, or trick users into signing malicious transactions under the guise of “agent economy” participation. The use of a reputable registrar like Dynadot and a valid SSL certificate lends false legitimacy, which is common in modern phishing campaigns targeting blockchain communities. If you visited vgb-dex.live, do not enter any credentials, connect your wallet, or approve transactions. Immediately revoke any connected wallet permissions via your wallet’s interface or a reputable revocation tool. Clear your browser cache and run a malware scan using trusted software. Report the domain to your antivirus provider and consider notifying the legitimate Vagachain team through their official channels. Always verify URLs manually and use bookmarked links or direct navigation to blockchain protocols—never click links from unsolicited messages. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260511-DCC8B8 Favicon MD5: 72ada65364c71f66063b709564520539 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/vgb-dex.live/ JSON API: https://api.destroy.tools/v1/check?domain=vgb-dex.live Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 157,760 domains (42,515 alive under monitoring, 114,275 confirmed takedowns/dead). Site: https://phishdestroy.io