# PhishDestroy threat dossier — globalmetainvest.com ================================================================ Fetched: 2026-07-31 21:41:02 UTC Canonical: https://phishdestroy.io/domain/globalmetainvest.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Investment Scam ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 5/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, CRDF, Gridinsoft, Netcraft, SOCRadar AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 208.109.191.182 (US, Tempe) ASN: AS398101 GoDaddy.com, LLC Hosting org: GoDaddy.com, LLC Registrar: GoDaddy.com, LLC Nameservers: ns1.muladev.online, ns2.muladev.online Registered: 2025-01-16 Expires: 2027-01-16 Page title: globalmetainvest.com HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-10-10 Status: INVALID chain Fingerprint: e1fcfc4b6187f05d09ea2b8dbb0145bbd81cb6166af11d379b1f4003e316702e Subject Alternative Names (related infrastructure — often same operator): - www.test.globalmetainvest.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-01-16 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 06:30:50 UTC (by PhishDestroy tracker) First reported: 2026-07-27 06:49:35 UTC (abuse notice filed) Last verified: 2026-07-31 20:20:27 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa1d6-5859-7009-b208-73436c0ce070/ URLQuery: https://urlquery.net/report/cb03712a-2f0c-4492-b405-fcb2d11e688e Wayback Machine: https://web.archive.org/web/*/globalmetainvest.com crt.sh CT logs: https://crt.sh/?q=%25.globalmetainvest.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=globalmetainvest.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/globalmetainvest.com URLhaus: https://urlhaus.abuse.ch/host/globalmetainvest.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 06:33:13 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] globalmetainvest.com Fake Investment Site Alert The domain globalmetainvest.com is currently classified as an active generic phishing operation. Infrastructure analysis shows the domain was registered through GoDaddy.com, LLC on January 16, 2025 and resolves to the IP address 208.109.191.182. Authoritative DNS resolution is provided by the nameservers ns1.muladev.online and ns2.muladev.online, which are not directly associated with the registrar and may indicate an attempt to obscure hosting relationships. Threat intelligence feeds have recorded a single detection by VirusTotal, where one of ninety‑one security vendors flagged the domain as malicious. The domain is listed on a security blocklist and has been actively blocked by the PhishDestroy service, reinforcing the assessment of malicious intent. No additional public evidence such as SSL certificate details, HTTP response codes, page titles, or explicit brand impersonation has been disclosed, leaving the specific content of the landing page unverified. The limited visibility of the site’s payload means that defenders cannot confirm the exact phishing vector, but the presence of a flagged detection and inclusion on blocklists suggest the site is likely used to harvest credentials or financial information under the guise of an investment platform. Organizations should continue to block traffic to the IP address 208.109.191.182 and to the domain name itself at the network perimeter, update endpoint protection signatures, and monitor for any outbound connections that reference the identified nameservers. Security teams are advised to treat any email or web traffic that references globalmetainvest.com as suspicious, enforce multi‑factor authentication for accounts that could be targeted, and consider sharing this indicator of compromise with threat‑sharing communities to assist broader mitigation efforts. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-BD1256 Favicon MD5: 35505e2ea39ece9bc5dff31e0fc72f70 TLS cert SHA-256: e1fcfc4b6187f05d09ea2b8dbb0145bbd81cb6166af11d379b1f4003e316702e ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/globalmetainvest.com/ JSON API: https://api.destroy.tools/v1/check?domain=globalmetainvest.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 196,675 domains (84,394 alive under monitoring, 27,268 confirmed neutralized). Site: https://phishdestroy.io