# PhishDestroy threat dossier — goldmin-crypto.com ================================================================ Fetched: 2026-07-29 12:30:26 UTC Canonical: https://phishdestroy.io/domain/goldmin-crypto.com/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 75/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Crypto.com ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 3/91 security vendors flagged this domain Flagging vendors: CRDF, Gridinsoft, SOCRadar AlienVault OTX: 1 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 199.36.158.100 (US, Mountain View) ASN: AS54113 Fastly, Inc. Hosting org: Google LLC Registrar: NAMECHEAP INC Nameservers: dns1.registrar-servers.com, dns2.registrar-servers.com Registered: 2026-06-04 Expires: 2027-06-04 Page title: Goldmin Crypto - Mobile App HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WR3 Expires: 2026-09-02 Status: INVALID chain Fingerprint: f898d4c206489747e71973e61dfb1ca4c7854e59d3403ea9f8bbec131408e934 Subject Alternative Names (related infrastructure — often same operator): - app.jiricech2059.com - apps.jb-energija.com - auth.tpdl.me - auth.vagoatelier.com - autocheck.report - badavabricks.in - capsexam.com - cbcpexam.com - cerebrito.colegios.com - cescpexam.com - cestexam.com - compliance-navigator.waldseeconsulting.ch - craft-ai.cloud - criatiwatecnologia.com.br - criexam.com ... +84 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-06-04 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 06:24:30 UTC (by PhishDestroy tracker) First reported: 2026-07-27 07:01:49 UTC (abuse notice filed) Last verified: 2026-07-29 12:20:31 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa1d0-0689-7305-b64c-bb218dcc37fb/ URLQuery: https://urlquery.net/report/0b611953-de06-414b-a4a0-e93f08912323 Wayback Machine: https://web.archive.org/web/*/goldmin-crypto.com crt.sh CT logs: https://crt.sh/?q=%25.goldmin-crypto.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=goldmin-crypto.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/goldmin-crypto.com URLhaus: https://urlhaus.abuse.ch/host/goldmin-crypto.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 06:26:05 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] goldmin-crypto.com crypto phishing site under investigation Analysis of goldmin-crypto.com indicates this domain is actively flagged as a phishing threat targeting cryptocurrency users. Registered on June 4, 2026, through NAMECHEAP INC, the domain resolves to IP address 199.36.158.100 and uses nameservers dns1.registrar-servers.com and dns2.registrar-servers.com. As of July 27, 2026, it appears on one security blocklist, with PhishDestroy currently blocking access. No detections were reported by the 91 vendors that scanned the domain on VirusTotal, though the absence of flags does not confirm safety. The domain remains active, and its exact content or phishing methodology has not yet been fully analyzed. Infrastructure review shows no additional hosting or SSL anomalies, but the registration timeline and blocklist inclusion suggest recent malicious intent. Defenders should treat this domain as a potential crypto-related phishing vector and consider blocking it at the network level. Further monitoring is required to determine if additional blocklists or detection vendors will flag it as the campaign evolves. No brand impersonation or specific phishing kit has been confirmed at this stage, and no Safe Browsing or OTX data is currently available for this domain. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-C4599C Favicon MD5: e38d7a210680f3bd3d2ff3d44f7ea8fa TLS cert SHA-256: f898d4c206489747e71973e61dfb1ca4c7854e59d3403ea9f8bbec131408e934 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/goldmin-crypto.com/ JSON API: https://api.destroy.tools/v1/check?domain=goldmin-crypto.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,406 domains (83,173 alive under monitoring, 109,716 confirmed takedowns/dead). Site: https://phishdestroy.io