PD-PYRAMID · 2026 Q2
Threat Death Pyramid
From a single suspicious URL at the tip — through every parser, scraper, ad-monitor, and the AI engine — down to a wide base of vendors, registrars, evidence stores, and the public ledger that records its death.
30+
Sources
50+
Vendors
194h
Avg TTM
105,588
Killed
tracking 179,996 domains · 458 new in 24h · live stats
L1Discovery Network
30+ ParsersCertStream · OpenPhish · URLhaus
poll · 60s1,247/h
hover · live cert example
CertStreamLet's Encrypt · live CT log
live
domainwww.antarctic.exchange
issuerLet's Encrypt R3
issued6 min ago · live in PhishDestroy DB
san*.www.antarctic.exchange
matchbrand("crypto") + intel sweep
→brand-impersonation certL3 / AI
Ads MonitorGoogle · Bing · DuckDuckGo
SERP sweep184/d
hover · live ad example
Google AdsSponsored · "metamask wallet"
live
Sponsored
MetaMask · metamαsk.io
MetaMask® — Official Wallet Login & Recovery Center
Restore your MetaMask wallet in 30 seconds. Verify your 12-word seed phrase to regain instant access. Trusted by 30M+ users worldwide.
→homoglyph "α" + seed-phrase baitL3 / AI
SEO ScrapersTop-100 wallet keywords
headless96/d
hover · organic result
Bing SearchOrganic · "uniswap support"
live
www.eigencloud.xyz › wallet
Crypto · Recovery & Support 24/7
Detected 6 min ago. Real impersonation domain currently in PhishDestroy active queue — soliciting seed phrases under brand-impersonation pretext.
→support-impersonation SEOL3 / AI
Domain Monitordnstwist · 92 brands
permutations412/d
hover · domain twist
dnstwistLookalike registration
live
phantom.appbaseline
phantorn.apphomoglyph
phantom-wallet.appaddition
phantorn-wallet.iocombo · new
→homoglyph + new TLDL3 / AI
Social MentionsYouTube · X · Reddit · Discord
74 channels53/h
hover · live stream
YouTube Live"Tesla AI Day" · 47K viewers
live
LIVE
47,238 watching
→deepfake livestream + 2× airdropL3 / AI
Community Bot@PhishDestroyBot · Telegram
intake28/h
hover · user submission
Telegram@PhishDestroyBot · /report
live
A
anon_4827@PhishDestroyBot
/report https://uniswap-airdrop.claim-eth.app
got DM from "support" claiming I won airdrop — asks to connect wallet + sign tx
got DM from "support" claiming I won airdrop — asks to connect wallet + sign tx
just now
→community-flagged airdropL3 / AI
L2Surfaced URL
Suspicious URL
L3AI Verification
L3 · PhishDestroy AI · Live
PhishDestroy AI
Multi-signal verification · false-positive guard · attribution model
- Verifying heuristics
- Capturing screenshots
- Validating metadata
Verdict
Confirmed phishing
94/ 100
confidence
Wallet drainer · MetaMask brand · WHOIS < 7d · cloaked geo-fence
Signals
- Heuristics
- Screenshot diff
- VT consensus
- Wallet drainer
- WHOIS < 7d
- Cloaked geo
L3·5Active Investigation
Code AnalysisJS deobfuscation · drainer signature
00:12 deobfuscate main.js · 4 layers
00:14 extract drainer.eth contract
00:16 match Inferno Drainer v3.2
signatures12 hits
Seed FloodTelegram drainer-bot · @claim_eth_bot
00:21 tg-flood fake seed × 247
00:23 poison drainer DB · noise 92%
00:25 bot-down operator switched
seeds sent12,418
Wallet Tracedrainer addr · on-chain analytics
00:31 trace 0x7a3...4f9 · 412 ETH
00:33 cluster linked 38 addresses
00:35 flag Tornado Cash hop
cluster38 addr
Evidence CaptureWARC · screenshots · DOM snapshot
00:41 capture WARC · 14.2 MB
00:43 snapshot DOM + 6 viewports
00:45 hash SHA256 · pinned IPFS
artifacts28 files
Evidence VaultPostgres · S3 · Merkle log
00:51 store case-id #PD-48217
00:53 index +ELK · attribution
00:55 commit Merkle root anchored
cases (30d)2,184
L4Global Vendor Sync
GoogleSafe Browsing
GoogleWeb Risk API
MicrosoftSmartScreen
VirusTotalDetection feed
CloudflareRadar / 1.1.1.1
YandexSafe Browsing
URLScan.ioPublic scan
ESETWebGuard
BitdefenderThreat exchange
NortonSafe Web
SymantecSiteReview
AviraCloud detection
Avast / AVGWeb Shield
KasperskyOpenTIP
Dr.WebOnline scanner
NetcraftTakedown API
PhishTankVerified vote
APWG eCXBulk feed
PhishStatsOpen feed
Phish.ReportHosting abuse
SpamhausDBL feed
PolySwarmMarketplace
CheckPhishBolster scan
QutteraMalware scan
URLquerySandbox
Criminal IPAsset intel
CRDFThreat Center
ScamadviserTrust score
MyWOTWeb of Trust
L5Pressure Channels
CH 01 · Push
Abuse Notifications
Registrar abuseRFC2142 · DKIM-signed
3 openHosting abuseARF + JSON
5 openICANN escalationCompliance ticket
AutoNameserver alertNS-level relay
2 openCH 02 · Seal
Forensic Evidence
Evidence packagetar.gz · S3 · WORM
SealedPDF reportCourt-ready
BuiltScreenshotsHeadless · 2× DPR
StoredMetadata logNDJSON · Merkle
AppendCH 03 · Broadcast
Public Channels
GitHubphishdestroy/db
PushedLive map/live · SSE
StreamedTwitter / X@phishdestroy
PostedTelegramt.me/phishdestroy
PostedMastodon@pd@infosec.exchange
PostedPublic APIapi.phishdestroy.io
LiveCH 04 · Loop
Re-detection
+6h retestSandbox replay
Active+12h retestGeo + UA matrix
Pending+24h retest2nd-wave abuse
QueuedAttribution graphKit · operator · cluster
LinkedL6Death & Public Record
Killed
Domain neutralized
DNS resolved → NXDOMAIN. Hosting suspended by registrar. Wallet flagged across all consumer browsers.
3h 42m
Time-to-kill
52
Vendors notified
$0
Stolen after kill
Recorded
Public record sealed
Committed to phishdestroy/db. Operator + kit linked to attribution cluster. Pinned in shame leaderboard.
#18472
Case ID
7
Linked domains
105,588
Total killed
Vendor sync
Abuse push
Evidence / loop
Public broadcast
105,588 killed ·
458 new in 24h ·
194h avg TTM ·
live