# PhishDestroy threat dossier — xn--ckwllt-wc8bc8se.com ================================================================ Fetched: 2026-07-26 20:20:35 UTC Canonical: https://phishdestroy.io/domain/xn--ckwllt-wc8bc8se.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 95/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain URLQuery: 2 detections Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 178.16.53.154 (NL, Amsterdam) ASN: AS202412 Omegatech LTD Hosting org: Omegatech LTD Registrar: NAMECHEAP INC Nameservers: ns1.gcorelabs.net, ns2.gcdn.services Registered: 2026-05-16 Expires: 2027-05-16 Page title: Cake Wallet: Security, Setup & Monero Wallet ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-10-15 Status: INVALID chain Fingerprint: ed9c7e349c8060b230b128acc3947a2d5252b1f89e925963d4df454a0adb8930 Subject Alternative Names (related infrastructure — often same operator): - www.xn--ckwllt-wc8bc8se.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-16 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-26 15:38:48 UTC (by PhishDestroy tracker) First reported: 2026-07-26 14:09:27 UTC (abuse notice filed) Last verified: 2026-07-26 20:45:54 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f9ea7-7ae1-73bc-917e-79820c9758aa/ URLQuery: https://urlquery.net/report/f4eb1f0c-a436-49dc-b9eb-fd5fcb57aab9 Wayback Machine: https://web.archive.org/web/*/xn--ckwllt-wc8bc8se.com crt.sh CT logs: https://crt.sh/?q=%25.xn--ckwllt-wc8bc8se.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=xn--ckwllt-wc8bc8se.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/xn--ckwllt-wc8bc8se.com URLhaus: https://urlhaus.abuse.ch/host/xn--ckwllt-wc8bc8se.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-26 15:39:09 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] xn--ckwllt-wc8bc8se.com — Generic Phishing Investigation The domain xn--ckwllt-wc8bc8se.com was registered through Namecheap Inc on May 16, 2026 and remains active as of the report date, July 26, 2026. DNS resolution points to the single IPv4 address 178.16.53.154, which is served by the authoritative name servers ns1.gcorelabs.net and ns2.gcdn.services. The domain is currently listed on three security blocklists and has been blocked by the PhishDestroy, MetaMask, and SEAL filtering services, indicating that multiple threat‑intelligence feeds have identified it as malicious. VirusTotal records show that the domain has been scanned by 91 antivirus and URL‑reputation vendors; none of the scanners returned a positive detection, but the absence of a detection does not constitute evidence of safety. The threat classification supplied is generic phishing, and the risk level is designated as high. No additional public metadata such as SSL certificate details, HTTP status codes, or page titles are available in the current intelligence set. Given the active status, the presence on blocklists, and the high‑risk rating, defenders should continue to block DNS resolution to 178.16.53.154, monitor for any traffic to the domain, and incorporate the domain into existing phishing‑mitigation rules. Ongoing observation of the hosting infrastructure and periodic rescans are recommended to detect any changes in the domain’s behavior or detection profile. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260726-95CD83 Favicon MD5: 5d8a6e4c02950994ad628e983815e4c2 TLS cert SHA-256: ed9c7e349c8060b230b128acc3947a2d5252b1f89e925963d4df454a0adb8930 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/xn--ckwllt-wc8bc8se.com/ JSON API: https://api.destroy.tools/v1/check?domain=xn--ckwllt-wc8bc8se.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 199,562 domains (68,854 alive under monitoring, 129,159 confirmed takedowns/dead). Site: https://phishdestroy.io