# PhishDestroy threat dossier — goldyield.info ================================================================ Fetched: 2026-07-27 11:18:59 UTC Canonical: https://phishdestroy.io/domain/goldyield.info/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 86/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 3/91 security vendors flagged this domain Flagging vendors: CRDF, Gridinsoft, Netcraft AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 198.54.116.65 (US, Los Angeles) ASN: AS22612 Namecheap, Inc. Hosting org: Namecheap, Inc. Registrar: NameCheap, Inc. Nameservers: dns1.namecheaphosting.com, dns2.namecheaphosting.com Registered: 2026-06-25 Expires: 2027-06-25 Page title: Home / GoldYield ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Sectigo Limited / Sectigo Public Server Authentication CA DV R36 Expires: 2027-01-10 Status: INVALID chain Fingerprint: be51fb910b15c20a851c3bd07584dd8ddbe3db15c3a778a9d7ff26c23af8e7d0 Subject Alternative Names (related infrastructure — often same operator): - www.goldyield.info ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-06-25 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 06:38:57 UTC (by PhishDestroy tracker) First reported: 2026-07-27 07:02:32 UTC (abuse notice filed) Last verified: 2026-07-27 13:15:04 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa2b3-4838-769a-b645-1d5710bbe7b4/ URLQuery: https://urlquery.net/report/d4ed2e39-2b3b-4ad8-b081-8e499d0c028e Wayback Machine: https://web.archive.org/web/*/goldyield.info crt.sh CT logs: https://crt.sh/?q=%25.goldyield.info Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=goldyield.info AlienVault OTX: https://otx.alienvault.com/indicator/domain/goldyield.info URLhaus: https://urlhaus.abuse.ch/host/goldyield.info/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 06:40:21 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] goldyield.info Safety Check — Phishing Detected goldyield.info is a newly registered domain (created 25 June 2026) hosted by NameCheap. The authoritative name servers dns1.namecheaphosting.com and dns2.namecheaphosting.com resolve the domain to IP 198.54.116.65. VirusTotal reports that three of ninety‑one scanning engines have flagged the domain, indicating malicious activity. The domain appears on a single external blocklist and is listed by PhishDestroy as an active phishing site. No additional public intelligence such as OTX tags, Safe Browsing alerts, or SSL certificate details are currently available. The registrar information confirms registration through NameCheap, Inc., a common service used by both legitimate and abusive actors. The infrastructure profile shows a single IPv4 address without known associated benign services, which further aligns with the observed malicious labeling. The combination of a recent creation date, detection by multiple AV vendors, inclusion on a phishing‑specific blocklist, and active status suggests a high confidence that goldyield.info is being used for phishing. However, the limited number of detections (three) and the presence on only one blocklist leave some uncertainty regarding the scale of the campaign and the exact payload delivered. Defenders should add the domain and its associated IP address to outbound web filtering rules, monitor DNS queries for the name servers, and consider pre‑emptive blocking in perimeter firewalls. Continuous re‑evaluation is advised, as additional detections or threat‑intel feeds may emerge. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-2F145E Favicon MD5: af5af69a03e1469dd07dbce41e1df683 TLS cert SHA-256: be51fb910b15c20a851c3bd07584dd8ddbe3db15c3a778a9d7ff26c23af8e7d0 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/goldyield.info/ JSON API: https://api.destroy.tools/v1/check?domain=goldyield.info Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 204,664 domains (79,861 alive under monitoring, 123,772 confirmed takedowns/dead). Site: https://phishdestroy.io