# PhishDestroy threat dossier — goldtrustltd.com ================================================================ Fetched: 2026-07-29 09:59:41 UTC Canonical: https://phishdestroy.io/domain/goldtrustltd.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 90/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 6/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, CRDF, Fortinet, Gridinsoft, Netcraft, SOCRadar AlienVault OTX: 1 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 79.133.41.61 (DE, Frankfurt am Main) ASN: AS214036 Ultahost, Inc. Hosting org: UltaHost Inc Registrar: Ultahost, Inc. Nameservers: ns1.ultahost.com, ns2.ultahost.com, ns3.ultahost.com, ns4.ultahost.com Registered: 2025-09-25 Expires: 2026-09-25 Page title: Gold Trust HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-10-04 Status: INVALID chain Fingerprint: 4deca8a927220607e7cc9258ea67f0436a334b9e8b8d865dbd022a1446b48ddc Subject Alternative Names (related infrastructure — often same operator): - cpanel.goldtrustltd.com - cpanel.trustsquareholdingltd.com - cpcalendars.goldtrustltd.com - cpcalendars.trustsquareholdingltd.com - cpcontacts.goldtrustltd.com - cpcontacts.trustsquareholdingltd.com - goldtrustltd.com.citystarglobalholdingsltd.com - mail.goldtrustltd.com - mail.trustsquareholdingltd.com - trustsquareholdingltd.com - trustsquareholdingltd.com.citystarglobalholdingsltd.com - webdisk.goldtrustltd.com - webdisk.trustsquareholdingltd.com - webmail.goldtrustltd.com - webmail.trustsquareholdingltd.com ... +4 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-09-25 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 06:24:34 UTC (by PhishDestroy tracker) First reported: 2026-07-27 07:02:03 UTC (abuse notice filed) Last verified: 2026-07-29 08:11:18 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa1d0-269b-706e-804e-7f2af291666c/ URLQuery: https://urlquery.net/report/c5cf7fe7-367b-4f10-81c9-b2ae86b7daf1 Wayback Machine: https://web.archive.org/web/*/goldtrustltd.com crt.sh CT logs: https://crt.sh/?q=%25.goldtrustltd.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=goldtrustltd.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/goldtrustltd.com URLhaus: https://urlhaus.abuse.ch/host/goldtrustltd.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 06:26:00 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] goldtrustltd.com Generic Phishing Alert goldtrustltd.com was registered on 25 September 2025 through Ultahost, Inc. The domain uses four authoritative name servers (ns1.ultahost.com, ns2.ultahost.com, ns3.ultahost.com, ns4.ultahost.com) and resolves to the IPv4 address 79.133.41.61. The IP is currently associated with a hosting provider that does not publish a public ASN in the supplied data, and no geolocation details are provided. The domain appears on a single public phishing blocklist; PhishDestroy has listed it as blocked. VirusTotal has processed the domain with 91 scanning engines and, as of the report date, no detections have been reported, though the absence of detections does not imply benign intent. No Safe Browsing, Open Threat Exchange, or other reputation services are referenced in the available intelligence. SSL/TLS configuration, HTTP response codes, page title, and any observed content have not been disclosed, leaving those vectors unverified. The lack of publicly available page metadata prevents confirmation of whether the site mimics a specific brand or service. Given the recent creation date, the presence on a phishing blocklist, and the dedicated hosting infrastructure, defenders should treat the domain as hostile. Recommended mitigations include adding goldtrustltd.com and its resolving IP 79.133.41.61 to network deny lists, enforcing URL filtering rules that block access to the domain, and monitoring DNS logs for queries to the domain or its name servers. Continuous re‑evaluation is advised, as future scans or threat‑intel feeds may reveal additional indicators such as SSL certificates, page content, or new blocklist listings. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-26F082 Favicon MD5: 16440540e7ed7a269b1cc1e31aad4227 TLS cert SHA-256: 4deca8a927220607e7cc9258ea67f0436a334b9e8b8d865dbd022a1446b48ddc ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/goldtrustltd.com/ JSON API: https://api.destroy.tools/v1/check?domain=goldtrustltd.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 194,525 domains (83,233 alive under monitoring, 108,559 confirmed takedowns/dead). Site: https://phishdestroy.io