Skip to content
View phishdestroy's full-sized avatar
🚨
Scammers will be caught, the time of reckoning has come!
🚨
Scammers will be caught, the time of reckoning has come!

Block or report phishdestroy

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
phishdestroy/README.md

PhishDestroy Banner

βš”οΈ PhishDestroy

Volunteer-Driven Threat Intelligence β€’ Infrastructure Takedowns β€’ OSINT Automation

Mission β€’ Operations β€’ Operational Matrix β€’ Projects β€’ Expertise β€’ Statistics β€’ Contact


🎯 Mission

PhishDestroy is a volunteer-driven threat intelligence initiative focused on large-scale detection, analysis, and elimination of:

  • Crypto drainers
  • Phishing networks
  • Scam infrastructure
  • Fraudulent applications
  • Threat actor clusters

Since 2019, we have:

  • Neutralized 500,000+ malicious domains
  • Eliminated 25+ actor-controlled infrastructures
  • Investigated 15+ threat actor groups
  • Maintained global OSINT feeds and takedown workflows

πŸ“Š Operations Overview

RECONNAISSANCE β”‚ β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ β”‚ CONTINUOUS
ANALYSIS β”‚ β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ β”‚ ACTIVE
COORDINATION β”‚ β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ β”‚ ONGOING
NEUTRALIZATION β”‚ β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ β”‚ RELENTLESS


πŸ›‘οΈ Operational Matrix

🌐 SCAN

β€’ CT logs monitoring
β€’ DNS anomaly detection
β€’ Passive DNS + feeds
β€’ Automated scanners
β€’ Community submissions

🎯 HUNT

β€’ Infra correlation
β€’ Actor attribution
β€’ Fingerprinting
β€’ Network graphing
β€’ Validation workflows

⚑ STRIKE

β€’ Registrar escalation
β€’ Hosting abuse pipeline
β€’ Null-routing requests
β€’ Evidence reporting
β€’ Multi-team ops

πŸ”₯ ERASE

β€’ Infra shutdown
β€’ Persistence monitoring
β€’ Re-emergence detection
β€’ Intelligence linking
β€’ Zero-tolerance control


πŸ“‘ Highlighted Projects


🧠 OSINT Detection Methods

  • Certificate Transparency API
  • DNS anomalies & registrar drift
  • Hosting & ASN correlation
  • Blockchain scam transaction analysis
  • Malware reverse engineering
  • AI-enhanced phishing kit detection
  • Automated intelligence clustering

🧩 Expertise & Stack


πŸ“ˆ Statistics & Activity

πŸ“Š More Stats


πŸ“¬ Contact & Community

Evidence-based threat neutralization since 2019
πŸ“§ github@phishdestroy.io
πŸ’ͺ Powered by volunteers, protected by community

Pinned Loading

  1. destroylist destroylist Public

    Real-time phishing & scam domain blocklist - 208k+ curated threats, 1M+ community, free API, multiple formats

    HTML 1.6k 419

  2. ScamIntelLogs ScamIntelLogs Public

    Open-source intelligence archive of crypto scam operations β€” internal chats, admin panels, victim records, and infrastructure data for research and investigation

    HTML 292 32

  3. DestroyScammers DestroyScammers Public

    Scam intelligence, phishing attribution, drainer mapping. Legal OSINT only. Public data. Real cases. For researchers and victims.

    JavaScript 254 20

  4. namesilo-evidence namesilo-evidence Public

    NameSilo (IANA #1479) registrar abuse investigation β€” 5,281,151 domains scanned, 204,460 classified IOC (122,119 HIGH), largely behind NameSilo's own PrivacyGuardian WHOIS shield. Filed with ICANN …

    HTML 130 19

  5. DO-NOT-USE-xmrwallet-com DO-NOT-USE-xmrwallet-com Public

    Forked from XMRWallet/Website

    ⚠️ xmrwallet.com steals your private view key on every request. Technical proof inside. If you lost funds β€” read LOST_FUNDS.md

    205 35

  6. trustname-evidence trustname-evidence Public

    Phase II evidence package: complete-zone scan of ICANN registrar #4318 Trustname.com / Fewmoretaps OÜ β€” 15,040 domains tracked, 4,276 classified IOC (3,293 HIGH). Daily updated IOC feeds, SIEM CSV,…

    Python 109 9