# PhishDestroy threat dossier — whitepill.life ================================================================ Fetched: 2026-07-22 21:35:25 UTC Canonical: https://phishdestroy.io/domain/whitepill.life/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 3/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Forcepoint ThreatSeeker, SOCRadar AlienVault OTX: 1 pulses (threat-intel feed mentions) Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 2.24.198.130 (US, Boston) ASN: AS47583 Hostinger International Limited Hosting org: Hostinger US Registrar: GoDaddy.com, LLC Nameservers: ns65.domaincontrol.com, ns66.domaincontrol.com Registered: 2026-02-23 Expires: 2027-02-23 Page title: Outreach Tracker · addicted.org HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE2 Expires: 2026-08-30 Status: INVALID chain Fingerprint: a080423db91de4336d523e089937d542bc37c28e6cd3af554cc2ce2d2dd0314c Subject Alternative Names (related infrastructure — often same operator): - www.whitepill.life ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-02-23 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-22 12:38:15 UTC (by PhishDestroy tracker) First reported: 2026-07-22 10:44:37 UTC (abuse notice filed) Last verified: 2026-07-22 20:20:23 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f8966-de29-70da-8c5a-110d7b5c3e9d/ URLQuery: https://urlquery.net/report/f32861f3-83ed-4d28-bbc9-6e7705bac9a4 Wayback Machine: https://web.archive.org/web/*/whitepill.life crt.sh CT logs: https://crt.sh/?q=%25.whitepill.life Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=whitepill.life AlienVault OTX: https://otx.alienvault.com/indicator/domain/whitepill.life URLhaus: https://urlhaus.abuse.ch/host/whitepill.life/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-22 12:38:52 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] whitepill.life: Confirmed Phishing Site The domain whitepill.life was registered on February 23, 2026 through GoDaddy.com, LLC and is currently resolving to the IPv4 address 2.24.198.130. Its authoritative name servers are ns65.domaincontrol.com and ns66.domaincontrol.com, both operated by GoDaddy’s DNS platform. Independent threat‑sharing services have flagged the domain as hostile: PhishDestroy, MetaMask, and SEAL have each added it to their blocklists, and it appears on three additional security blocklists. VirusTotal analysis shows that three of ninety‑five scanned security engines have identified malicious behavior associated with the domain, reinforcing the suspicion of illicit activity. The domain’s status remains active as of the report date, July 22, 2026, and no evidence of takedown has been observed. No public information about the site’s SSL certificate, HTTP response codes, page title, or targeted brand is available, leaving the exact content and lure mechanisms undocumented. Consequently, the primary confidence derives from the multi‑vendor detections, blocklist listings, and the recent creation date that aligns with typical phishing campaign lifecycles. Defenders should block traffic to whitepill.life at perimeter devices, update URL filtering and DNS sinkhole rules, and monitor for any outbound connections to the associated IP address. Analysts should continue to collect payloads or screenshots if the site is accessed in a controlled environment to enrich the indicator set and confirm the specific phishing vector employed. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260722-CA32B9 TLS cert SHA-256: a080423db91de4336d523e089937d542bc37c28e6cd3af554cc2ce2d2dd0314c ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/whitepill.life/ JSON API: https://api.destroy.tools/v1/check?domain=whitepill.life Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 188,426 domains (57,871 alive under monitoring, 128,922 confirmed takedowns/dead). Site: https://phishdestroy.io