# PhishDestroy threat dossier — yxzdw.cn ================================================================ Fetched: 2026-06-27 09:34:00 UTC Canonical: https://phishdestroy.io/domain/yxzdw.cn/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Credential Phishing ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 21/94 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar, Fortinet, G-Data, Google Safebrowsing, Netcraft, PhishLabs, Sophos URLQuery: 3 detections AlienVault OTX: 1 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist Google Safe Browsing: FLAGGED ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 161.248.14.214 (MY, Kuala Lumpur) ASN: AS4907 BGPNET PTE. LTD. Hosting org: Netforge Solution Sdn. Bhd Registrar: Web Commerce Communications Limited Nameservers: a.share-dns.com, a2.share-dns.com, b.share-dns.net, b2.share-dns.net Registered: 2025-11-27 Page title: Apache Tomcat/9.0.65 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R13 Expires: 2026-06-30 Status: INVALID chain Fingerprint: 5bee2b216922286f7b6b0fea79da6f9d3a5d230e4c1e1057ebd7c371b1787451 Subject Alternative Names (related infrastructure — often same operator): - eadgc.cn ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-11-27 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-25 03:09:25 UTC (by PhishDestroy tracker) First reported: 2026-04-25 00:11:08 UTC (abuse notice filed) Last verified: 2026-06-27 08:20:34 UTC Neutralised: 2026-05-15 21:14:49 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019dc1f6-3912-7600-90ff-c02986ff1854/ URLQuery: https://urlquery.net/report/f4d9e4cd-4162-4370-b173-97de906d1475 Wayback Machine: https://web.archive.org/web/*/yxzdw.cn crt.sh CT logs: https://crt.sh/?q=%25.yxzdw.cn Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=yxzdw.cn AlienVault OTX: https://otx.alienvault.com/indicator/domain/yxzdw.cn URLhaus: https://urlhaus.abuse.ch/host/yxzdw.cn/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-25 20:49:09 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] This domain, yxzdw.cn, is identified as a credential theft operation designed to harvest login credentials, payment details, or other sensitive user data. Such sites often mimic legitimate services, tricking visitors into entering personal information under false pretenses. The threat is particularly dangerous for users who may unknowingly disclose credentials, leading to account takeovers, financial fraud, or identity theft. Given its high-risk classification, interaction with this domain should be avoided entirely. Analysis indicates yxzdw.cn was created on November 27, 2025, an unusually future-dated registration that suggests potential domain spoofing or fraudulent activity. The domain is hosted on IP address 161.248.14.214, located in Malaysia and associated with Netforge Solution Sdn. Bhd, a provider frequently linked to malicious infrastructure. Security vendors on VirusTotal flagged the domain, with 21 out of 95 engines detecting it as malicious. The site was registered through Web Commerce Communications Limited, a registrar often exploited for phishing campaigns. Additionally, the page title, Apache Tomcat/9.0.65, may indicate an attempt to exploit vulnerabilities in outdated server software or mislead users about the site's legitimacy. If you visited yxzdw.cn, immediate action is required to mitigate potential risks. First, disconnect the device from the network to prevent further data exfiltration. Run a full scan using updated security software to detect and remove any malware or spyware. Change passwords for all accounts accessed from the compromised device, prioritizing financial, email, and social media platforms. Enable multi-factor authentication where available to add an extra layer of security. Monitor accounts for unauthorized transactions or suspicious activity, and consider placing a fraud alert on credit reports if financial information was entered. Finally, report the domain to relevant cybersecurity authorities or incident response teams to assist in broader threat mitigation efforts. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260425-34AFA4 Favicon MD5: d24ebcd28e1beee5b87805ae064c2447 TLS cert SHA-256: 5bee2b216922286f7b6b0fea79da6f9d3a5d230e4c1e1057ebd7c371b1787451 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/yxzdw.cn/ JSON API: https://api.destroy.tools/v1/check?domain=yxzdw.cn Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 170,806 domains (12,465 alive under monitoring, 157,937 confirmed takedowns/dead). Site: https://phishdestroy.io