PhishDestroy first observed toahax.com on Jul 28, 2026. Stored content metadata identifies Cryptoscam as the apparent target. Stored page analysis classifies the content as credential phishing. Current evidence score: 100/100 (critical).
Positive findings are stored from 5 sources: VirusTotal, MetaMask, ScamSniffer, SEAL, and URLScan. VirusTotal recorded 13 detections among 91 engines: alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Kaspersky, LevelBlue, Netcraft, SOCRadar, Sophos on Aug 7, 2026 at 02:12 UTC. MetaMask, ScamSniffer, and SEAL listed the hostname in the separate external-blocklist snapshot on Aug 8, 2026 at 14:20 UTC. URLScan returned a malicious verdict with score 100; scan metadata assigned phishing as its category on Jul 29, 2026 at 02:23 UTC. Non-positive and contextual checks: Gridinsoft assigned a trust score of 1/100; no observation timestamp was retained. Google Safe Browsing returned no flag on Jul 28, 2026 at 18:00 UTC.
HTTP 200 was recorded on Aug 8, 2026 at 10:40 UTC. Registration records for the domain list Fewmoretaps OU d/b/a Trustname.com as the registrar and Jul 23, 2026 as the creation date. Registration preceded first observation by 5 days. At collection time, the hostname resolved to 64.7.198.11 on AS399629 (BL Networks). The IP and ASN identify shared Cloudflare edge infrastructure; the origin server is not established by this address. DOM analysis on Jul 28, 2026 at 18:20 UTC returned 88/100. The evidence archive retains 2 visual captures from PhishDestroy and URLScan; no page title was retained, so the captures preserve the landing-page appearance. TLS metadata lists Let's Encrypt as the certificate issuer with validity through Oct 26, 2026; checked Jul 28, 2026 at 19:02 UTC.
The content indicators and 5 positive source findings support the current Cryptoscam-themed credential phishing classification.