# PhishDestroy threat dossier — xoilaczz35.live ================================================================ Fetched: 2026-07-24 04:30:17 UTC Canonical: https://phishdestroy.io/domain/xoilaczz35.live/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 66/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 15/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, Antiy-AVL, BitDefender, Chong Lua Dao, CRDF, CyRadar, ESET, Fortinet, G-Data, Gridinsoft, Lionic, Sophos, VIPRE, Webroot URLQuery: 7 detections AlienVault OTX: 1 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.67.186.225 (US, San Francisco) Hosting org: AS13335 Cloudflare, Inc. Registrar: GoDaddy.com, LLC Nameservers: ernest.ns.cloudflare.com, norah.ns.cloudflare.com Registered: 2024-07-04 Expires: 2027-07-04 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-10-22 Status: INVALID chain Fingerprint: 430cd61649bd44154235d23181805304a32308317cda6288a64db557f7bb66c1 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2024-07-04 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-24 03:37:35 UTC (by PhishDestroy tracker) First reported: 2026-07-24 01:40:40 UTC (abuse notice filed) Last verified: 2026-07-24 06:02:03 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f91c4-a105-7005-ab60-4d85ab98e5d8/ URLQuery: https://urlquery.net/report/33fd06cc-6761-4685-9404-426eb475e246 Wayback Machine: https://web.archive.org/web/*/xoilaczz35.live crt.sh CT logs: https://crt.sh/?q=%25.xoilaczz35.live Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=xoilaczz35.live AlienVault OTX: https://otx.alienvault.com/indicator/domain/xoilaczz35.live URLhaus: https://urlhaus.abuse.ch/host/xoilaczz35.live/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-24 03:39:00 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] xoilaczz35.live Used for High-Risk Credential Theft Attempts As of July 24, 2026, xoilaczz35.live is assessed as a high-risk domain for credential theft based on multiple sources of technical evidence. The domain was registered on July 4, 2024, via GoDaddy.com, LLC, and remains active. Analysis reveals that it resolves to IP address 172.67.186.225 and utilizes Cloudflare nameservers (ernest.ns.cloudflare.com and norah.ns.cloudflare.com), which is a common configuration among malicious domains aiming to obscure server infrastructure and mask the origin of traffic. Fifteen out of ninety-one security vendors on VirusTotal currently flag this domain for phishing or similar threats, providing a clear consensus among threat intelligence providers. The domain is also blocked by PhishDestroy and appears on at least one known security blocklist. Despite these findings, the specific content and tactics used on xoilaczz35.live have not been directly observed or analyzed, so the exact nature of the phishing pages or targeted credentials remains unconfirmed. There are no identified references to Safe Browsing, OTX, SSL certificate details, or additional infrastructure attributes in the available intelligence. No brand or scam kit associations are present in the data, and the page title and HTTP response status have not been provided. Given the domain's recent creation, rapid appearance on blocklists, and continued operation, defenders are strongly advised to treat all traffic to xoilaczz35.live as hostile. Immediate blocking at perimeter controls is recommended, and any observed interaction with this domain within enterprise environments should trigger investigation for possible credential compromise or lateral movement. Further analysis should be conducted if additional technical artifacts become available. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260724-A568BD TLS cert SHA-256: 430cd61649bd44154235d23181805304a32308317cda6288a64db557f7bb66c1 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/xoilaczz35.live/ JSON API: https://api.destroy.tools/v1/check?domain=xoilaczz35.live Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 188,977 domains (58,404 alive under monitoring, 128,955 confirmed takedowns/dead). Site: https://phishdestroy.io