PD-PYRAMID · 2026 Q2
Threat Death Pyramid
From a single suspicious URL at the tip — through every parser, scraper, ad-monitor, and the AI engine — down to a wide base of vendors, registrars, evidence stores, and the public ledger that records its death.
30+
Sources
29
Scan / report services
—
Avg TTM · 90d
27,311
Confirmed
tracking 214,934 domains · 107 new in 24h · TTM sample: 0 confirmed records
L1Discovery Network
30+ ParsersCertStream · OpenPhish · URLhaus
poll · 60s—
hovertap · live cert example
CertStreamLet's Encrypt · live CT log
live
domainconneectipss.info
issuerLet's Encrypt R3
issued101 min ago · live in PhishDestroy DB
san*.conneectipss.info
matchbrand("crypto") + intel sweep
→brand-impersonation certL3 / AI
Ads MonitorGoogle · Bing · DuckDuckGo
SERP sweep—
hovertap · live ad example
Google AdsSponsored · "metamask wallet"
live
Sponsored
MetaMask · metamαsk.io
MetaMask® — Official Wallet Login & Recovery Center
Restore your MetaMask wallet in 30 seconds. Verify your 12-word seed phrase to regain instant access. Trusted by 30M+ users worldwide.
→homoglyph "α" + seed-phrase baitL3 / AI
SEO ScrapersTop-100 wallet keywords
headless—
hovertap · organic result
Bing SearchOrganic · "uniswap support"
live
trustholdingsbnk.com › wallet
Crypto · Recovery & Support 24/7
Detected 299 min ago. Real impersonation domain currently in PhishDestroy active queue — soliciting seed phrases under brand-impersonation pretext.
→support-impersonation SEOL3 / AI
Domain Monitordnstwist · 92 brands
permutations—
hovertap · domain twist
dnstwistLookalike registration
live
phantom.appbaseline
phantorn.apphomoglyph
phantom-wallet.appaddition
phantorn-wallet.iocombo · new
→homoglyph + new TLDL3 / AI
Social MentionsYouTube · X · Reddit · Discord
74 channels—
hovertap · live stream
YouTube Live"Tesla AI Day" · 47K viewers
live
LIVE
47,238 watching
→deepfake livestream + 2× airdropL3 / AI
Community Bot@PhishDestroyBot · Telegram
intake—
hovertap · user submission
Telegram@PhishDestroyBot · /report
live
A
anon_4827@PhishDestroyBot
/report https://uniswap-airdrop.claim-eth.app
got DM from "support" claiming I won airdrop — asks to connect wallet + sign tx
got DM from "support" claiming I won airdrop — asks to connect wallet + sign tx
just now
→community-flagged airdropL3 / AI
L2Surfaced URL
Suspicious URL
L3AI Verification
L3 · PhishDestroy AI · Live
PhishDestroy AI
Multi-signal verification · false-positive guard · attribution model
- Verifying heuristics
- Capturing screenshots
- Validating metadata
Verdict
Confirmed phishing
94/ 100
confidence
Wallet drainer · MetaMask brand · WHOIS < 7d · cloaked geo-fence
Signals
- Heuristics
- Screenshot diff
- VT consensus
- Wallet drainer
- WHOIS < 7d
- Cloaked geo
L3·5Active Investigation
Code AnalysisJS deobfuscation · drainer signature
00:12 deobfuscate main.js · 4 layers
00:14 extract drainer.eth contract
00:16 match Inferno Drainer v3.2
signatures12 hits
Public Scan EvidenceIndependent scanners · archived results
urlscan.ioScreenshot · DOM · HTTP
VirusTotalEngine verdicts · analysis date
RadarPublic scan · infrastructure
Evidence sourcesPublic records
Wallet Tracedrainer addr · on-chain analytics
00:31 trace 0x7a3...4f9 · 412 ETH
00:33 cluster linked 38 addresses
00:35 flag Tornado Cash hop
cluster38 addr
Evidence CaptureWARC · screenshots · DOM snapshot
00:41 capture WARC · 14.2 MB
00:43 snapshot DOM + 6 viewports
00:45 hash SHA256 · pinned IPFS
artifacts28 files
Evidence VaultPostgres · S3 · Merkle log
00:51 store case-id #PD-48217
00:53 index +ELK · attribution
00:55 commit Merkle root anchored
cases (30d)2,184
We use public scanners, reputation checks and reporting channels. These are separate services, not a synchronized partner network. For a specific domain, inspect its stored scans and outgoing report history.
L4Public Scans & Security Reports
GoogleSafe Browsing
GoogleWeb Risk API
MicrosoftSmartScreen
VirusTotalDetection feed
CloudflareRadar / 1.1.1.1
YandexSafe Browsing
URLScan.ioPublic scan
ESETWebGuard
BitdefenderThreat exchange
NortonSafe Web
SymantecSiteReview
AviraCloud detection
Avast / AVGWeb Shield
KasperskyOpenTIP
Dr.WebOnline scanner
NetcraftTakedown API
PhishTankVerified vote
APWG eCXBulk feed
PhishStatsOpen feed
Phish.ReportHosting abuse
SpamhausDBL feed
PolySwarmMarketplace
CheckPhishBolster scan
QutteraMalware scan
URLquerySandbox
Criminal IPAsset intel
CRDFThreat Center
ScamadviserTrust score
MyWOTWeb of Trust
L5Pressure Channels
CH 01 · Push
Abuse Notifications
Registrar abuseRFC2142 · DKIM-signed
3 openHosting abuseARF + JSON
5 openICANN escalationCompliance ticket
AutoNameserver alertNS-level relay
2 openCH 02 · Seal
Forensic Evidence
Evidence packagetar.gz · S3 · WORM
SealedPDF reportCourt-ready
BuiltScreenshotsHeadless · 2× DPR
StoredMetadata logNDJSON · Merkle
AppendCH 03 · Broadcast
Public Channels
GitHubphishdestroy/db
PushedLive map/live · SSE
StreamedTwitter / X@phishdestroy
PostedTelegramt.me/phishdestroy
PostedMastodon@pd@infosec.exchange
PostedPublic APIapi.phishdestroy.io
LiveCH 04 · Loop
Re-detection
+6h retestSandbox replay
Active+12h retestGeo + UA matrix
Pending+24h retest2nd-wave abuse
QueuedAttribution graphKit · operator · cluster
LinkedL6Death & Public Record
Illustrative outcome
Example: domain made unavailable
DNS resolved → NXDOMAIN. Hosting suspended by registrar. Wallet flagged across all consumer browsers.
3h 42m
Time-to-kill
52
Vendors notified
$0
Stolen after kill
Recorded
Public record sealed
Committed to phishdestroy/db. Operator + kit linked to attribution cluster. Pinned in shame leaderboard.
#18472
Case ID
7
Linked domains
27,311
Total killed
Vendor sync
Abuse push
Evidence / loop
Public broadcast
27,311 confirmed takedowns ·
107 new in 24h ·
— avg TTM ·
live