PhishDestroy first observed bestforexthrive.com on Jul 30, 2026. Stored content metadata identifies Across as the apparent target. The captured page title is “Bestforexthrive | CFD Trading — Trading on Stocks, Gold, Oil, Indices”. Page analysis recorded additional brand references to Ethereum, Ledger, and LinkedIn. Stored page analysis classifies the content as impersonation. Current evidence score: 89/100 (critical).
Positive findings are stored from 3 sources: VirusTotal, Spamhaus DBL, and URLScan. VirusTotal recorded 8 detections among 91 engines: alphaMountain.ai, CRDF, CyRadar, Forcepoint ThreatSeeker, Fortinet, Gridinsoft, Netcraft, SOCRadar on Aug 1, 2026 at 02:11 UTC. Spamhaus DBL: DBL_SPAM on Jul 30, 2026 at 22:30 UTC. URLScan returned a malicious verdict with score 100; scan metadata assigned phishing as its category on Aug 1, 2026 at 03:30 UTC. Non-positive and contextual checks: Gridinsoft assigned a trust score of 1/100; no observation timestamp was retained. The separate external-blocklist snapshot contained no matches on Aug 8, 2026 at 10:20 UTC. URLQuery recorded no positive detection on Jul 30, 2026 at 21:23 UTC. Google Safe Browsing returned no flag on Jul 30, 2026 at 21:16 UTC.
HTTP 200 was recorded on Aug 8, 2026 at 10:09 UTC. Registration records for the domain list Ultahost, Inc. as the registrar and Jul 18, 2026 as the creation date. Registration preceded first observation by 11 days. At collection time, the hostname resolved to 159.100.6.19 on AS214036 (Ultahost, Inc.). The recorded endpoint location is Frankfurt am Main, DE. The stored server header is LiteSpeed. DOM analysis on Jul 30, 2026 at 22:20 UTC returned 76/100. The evidence archive retains 3 visual captures from PhishDestroy, URLScan, and URLQuery. TLS metadata lists Let's Encrypt as the certificate issuer with validity through Oct 16, 2026; checked Jul 30, 2026 at 22:02 UTC.
The content indicators and 3 positive source findings support the current Across-themed impersonation classification.