# PhishDestroy threat dossier — yield-system.com ================================================================ Fetched: 2026-07-24 00:52:01 UTC Canonical: https://phishdestroy.io/domain/yield-system.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/91 security vendors flagged this domain URLQuery: 2 detections Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 192.0.78.20 (US, San Francisco) ASN: ASAS2635 AUTOMATTIC - Automattic, Inc, US Hosting org: AS2635 Automattic, Inc Registrar: Automattic Inc. Nameservers: ns1.wordpress.com, ns2.wordpress.com, ns3.wordpress.com Registered: 2026-07-01 Expires: 2027-07-01 Page title: yield-system.com HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WR1 Expires: 2026-09-29 Status: INVALID chain Fingerprint: 35384453060157472ae0b03caf3ac5afa93da34b7826a7937c5b75794d2bf287 Subject Alternative Names (related infrastructure — often same operator): - tls.automattic.com - www.yield-system.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-01 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-03 07:19:52 UTC (by PhishDestroy tracker) First reported: 2026-07-03 05:25:14 UTC (abuse notice filed) Last verified: 2026-07-24 00:20:33 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f266a-25b1-765e-8276-6dab706b23fc/ URLQuery: https://urlquery.net/report/39423b57-d867-4253-b5da-692a8a86adf4 Wayback Machine: https://web.archive.org/web/*/yield-system.com crt.sh CT logs: https://crt.sh/?q=%25.yield-system.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=yield-system.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/yield-system.com URLhaus: https://urlhaus.abuse.ch/host/yield-system.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-03 07:26:25 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] yield-system.com Safety Check — Fake Page Loader Phishing This domain, yield-system.com, is flagged as a generic phishing threat designed to simulate a "Problem loading page" error. Analysis indicates no direct association with known brand impersonation or crypto drainer kits, but the page title suggests an attempt to deceive users into believing a legitimate service failed to load, potentially redirecting them to malicious content. No specific phishing kit or payload has been identified at this stage, though the behavior aligns with low-interaction phishing infrastructure. Infrastructure analysis reveals the following technical indicators: the domain was registered on July 01, 2026, through Automattic Inc., and currently resolves to the IP address 192.0.78.24. VirusTotal detections stand at 0/95, indicating no antivirus engines have flagged the domain as malicious at the time of this report. The domain is not listed in Google Safe Browsing, and no blocklist entries have been recorded. The SSL certificate is issued by Google Trust Services, which does not inherently indicate malicious activity but is often leveraged in phishing campaigns to appear legitimate. The domain remains active and under investigation, with no takedown or sinkholing actions observed. Response actions include continuous monitoring for changes in detection status, payload delivery, or shifts in infrastructure. The remaining risk is classified as elevated due to the domain's active status, lack of detection by security vendors, and potential for future malicious use. Organizations are advised to block the domain at the DNS or proxy level and monitor for connections to 192.0.78.24. End users should avoid interacting with the domain and report any suspicious redirects or pop-ups associated with it. [Updates since narrative was generated:] - Public blocklists: now listed on 3 feeds - VirusTotal detections: now 2/91 (narrative was written when count was lower) ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260703-1203FA Favicon MD5: f1b192a0d533d4a7d891a5f28b00c90e TLS cert SHA-256: 35384453060157472ae0b03caf3ac5afa93da34b7826a7937c5b75794d2bf287 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/yield-system.com/ JSON API: https://api.destroy.tools/v1/check?domain=yield-system.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 188,965 domains (58,392 alive under monitoring, 128,955 confirmed takedowns/dead). Site: https://phishdestroy.io