# PhishDestroy threat dossier — webtrader.inblocks-ai.com ================================================================ Fetched: 2026-06-07 12:22:41 UTC Canonical: https://phishdestroy.io/domain/webtrader.inblocks-ai.com/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 80/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 199.231.235.157 (NL, Amsterdam) ASN: AS210083 Privex Inc. Hosting org: Privex Inc Registrar: NameSilo, LLC !!! REGISTRAR INTEGRITY ALERT — NameSilo !!! NameSilo is a registrar documented by PhishDestroy as (1) publicly lying about received abuse reports, (2) shielding a $20M+ Monero-theft operation (xmrwallet.com) for 10 continuous years, and (3) retaliating against PhishDestroy by getting our X/Twitter account @Phish_Destroy banned after we published the evidence. Researchers/victims must ALWAYS CC compliance@icann.org on every abuse ticket — NameSilo has a track record of later claiming reports were never received. Primary sources: https://phishdestroy.io/namesilo-killed-our-twitter https://phishdestroy.io/xmrwallet-namesilo-exposed Nameservers: ["dolly.ns.cloudflare.com", "roan.ns.cloudflare.com"] Registered: 2026-04-27 Page title: Webtrader ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Sectigo Limited / Sectigo Public Server Authentication CA DV R36 Expires: 2026-10-03 Status: INVALID chain Fingerprint: e788e746ed0a672f80f765c222f887ddbfb10662b4f80340f1b26efbd53f3d41 Subject Alternative Names (related infrastructure — often same operator): - inblocks-ai.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-27 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-27 20:12:15 UTC (by PhishDestroy tracker) Earliest abuse rec: 2026-04-27 17:13:33 UTC — PREDATES current WHOIS registration; retained from a previous registration cycle of the same domain name Last verified: 2026-06-02 17:20:40 UTC Neutralised: 2026-04-29 09:27:45 UTC Current status: taken down (registrar suspended or DNS dead) Note: one or more events above predate the WHOIS creation date. This typically means the same domain name was previously registered, detected, dropped, and then re-registered by a new party. PhishDestroy preserves the full historical record for operator-attribution research even when the underlying infrastructure changes hands. ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019dcfeb-97aa-7410-a32e-8aee44b120e9/ URLQuery: https://urlquery.net/report/c619c06f-0bae-4ad6-9aa9-67b55064e89d Wayback Machine: https://web.archive.org/web/*/webtrader.inblocks-ai.com crt.sh CT logs: https://crt.sh/?q=%25.webtrader.inblocks-ai.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=webtrader.inblocks-ai.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/webtrader.inblocks-ai.com URLhaus: https://urlhaus.abuse.ch/host/webtrader.inblocks-ai.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-27 20:13:29 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies the active domain webtrader.inblocks-ai.com as a generic phishing page impersonating an online trading platform, likely targeting cryptocurrency users seeking portfolio management or asset trading. This domain employs a crypto-related theme ("webtrader") to deceive visitors into connecting their digital wallets under the false pretense of asset or trading functionality. No specific drainer kit or branding spoofing has been confirmed at this stage, but the convergence of domain semantics with high-risk behavior patterns suggests imminent credential theft or wallet draining activities. The infrastructure is provisioned to host a convincing fake UI mirroring legitimate trading dashboards, increasing the likelihood of user interaction and data exposure. This domain exhibits several concerning technical indicators flagged during forensic analysis. webtrader.inblocks-ai.com resolves to IP address 199.231.235.157 and is registered via NameSilo, LLC, with a creation timestamp of December 31, 2025 — a recent and potentially suspicious date given the absence of historical legitimacy. The SSL certificate, issued by Sectigo Limited, does not mitigate risk as it is commonly abused in phishing campaigns to simulate trust. According to VirusTotal intelligence, the domain currently shows 0 detections out of 95 engines as of real-time scanning, indicating it remains unflagged by most security platforms despite active hosting. While Google Safe Browsing (GSB) status and third-party blocklist participation are not confirmed in this dataset, such low detection rates are consistent with emerging phishing domains designed to bypass early-stage detection systems. The domain’s anonymity-friendly registration and recent creation strongly correlate with malicious intent, warranting immediate scrutiny. As of this report, the domain remains active and under active monitoring by PhishDestroy’s threat intelligence unit. The current risk level is tagged as "under_investigation," but the absence of detections and presence of suspicious infrastructure suggest escalation potential. Users are strongly advised to avoid visiting webtrader.inblocks-ai.com and to verify any trading-related domains via official sources before interaction. The domain’s block status and associated infrastructures (IP, SSL) should be disseminated to network defense teams and security vendors to preempt mass compromise. Remaining risk is assessed as moderate-to-high due to the combination of novel infrastructure, low detection coverage, and thematic alignment with high-value phishing targets in the cryptocurrency sector. Disruption efforts include domain takedown coordination, IP/SSL blacklisting, and alert distribution to crypto communities. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260427-806AF5 Favicon MD5: aa60ecb41b36f109b9ca6cb0abf8446b TLS cert SHA-256: e788e746ed0a672f80f765c222f887ddbfb10662b4f80340f1b26efbd53f3d41 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/webtrader.inblocks-ai.com/ JSON API: https://api.destroy.tools/v1/check?domain=webtrader.inblocks-ai.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 157,770 domains (42,445 alive under monitoring, 114,242 confirmed takedowns/dead). Site: https://phishdestroy.io