# PhishDestroy threat dossier — your-caio.com ================================================================ Fetched: 2026-05-19 14:11:42 UTC Canonical: https://phishdestroy.io/domain/your-caio.com/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: MetaMask Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users (type: content_split) (score: 1/6) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/92 security vendors flagged this domain Public blocklists: listed on 2 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.97.3 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: CloudFlare, Inc. Registrar: Spaceship, Inc. Nameservers: lynn.ns.cloudflare.com, walk.ns.cloudflare.com Registered: 2026-05-07 Page title: David Cartolano: AI Automation for Self-Storage | Your CAIO ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E7 Expires: 2026-08-06 Status: INVALID chain Fingerprint: 34349d95290e842c1b36eb0b2c9f3f0da0f76fa4d79f658b3eb81a29740b7ae4 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-07 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-08 17:22:07 UTC (by PhishDestroy tracker) Last verified: 2026-05-16 19:40:03 UTC Neutralised: 2026-05-10 02:59:42 UTC Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e07f3-e150-73f5-8c63-40cc296e3c13/ Wayback Machine: https://web.archive.org/web/*/your-caio.com crt.sh CT logs: https://crt.sh/?q=%25.your-caio.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=your-caio.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/your-caio.com URLhaus: https://urlhaus.abuse.ch/host/your-caio.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-08 17:22:29 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies your-caio.com as an active crypto-draining phishing domain engineered to siphon cryptocurrency from unsuspecting wallet users. The payload is delivered through fake wallet-login portals that silently approve malicious token approval transactions the moment the victim connects, draining balances in under 30 seconds. This domain should be treated as hostile infrastructure and avoided entirely. This domain was flagged by PhishDestroy after MetaMask and SEAL independently blocked access, indicating confirmed malicious intent. The domain was registered on May 07, 2026 through Spaceship, Inc., resolving to a Cloudflare IP at 188.114.97.3. The SSL certificate was issued by Let’s Encrypt, showing no signs of revocation despite the domain’s malicious activity. VirusTotal currently returns 0 detections out of 95 scanners, highlighting a significant window of opportunity for threat actors to operate undetected. Additionally, your-caio.com has already appeared on two public threat intelligence blocklists, underscoring its rapid escalation from newly registered to widely recognized malicious host. Mitigation for this specific crypto drainer threat requires immediate defensive actions. Users must refrain from visiting or interacting with any URL containing your-caio.com and should avoid clicking links received via unsolicited emails, social media messages, or Discord/Twitter DMs. If a connection attempt was made, disconnect the wallet immediately, revoke any unauthorized token approvals via tools like revoke.cash or your wallet’s built-in “Revoke Permissions” feature, and monitor on-chain activity for outgoing transfers. Organizations should update browser and DNS filters to block the domain and its IP range, while wallet extensions and dApps should integrate real-time reputation checks against blocklists to prevent users from signing malicious transactions. The combination of low detection rates and high operational tempo demands proactive blocking and user education to prevent financial loss. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: c30c7d42707a47a3f4591831641e50dc TLS cert SHA-256: 34349d95290e842c1b36eb0b2c9f3f0da0f76fa4d79f658b3eb81a29740b7ae4 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/your-caio.com/ JSON API: https://api.destroy.tools/v1/check?domain=your-caio.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 151,547 domains (44,263 alive under monitoring, 106,999 confirmed takedowns/dead). Site: https://phishdestroy.io