# PhishDestroy threat dossier — golemtrade.com ================================================================ Fetched: 2026-07-28 23:51:51 UTC Canonical: https://phishdestroy.io/domain/golemtrade.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 8/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, CRDF, CyRadar, Fortinet, Google Safe Browsing, Gridinsoft, Seclookup Public blocklists: listed on 1 independent blocklist Google Safe Browsing: FLAGGED ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 209.74.67.97 (SG, Singapore) ASN: AS22612 Namecheap, Inc. Hosting org: Namecheap Inc Registrar: NAMECHEAP INC Nameservers: dns1.namecheaphosting.com, dns2.namecheaphosting.com Registered: 2025-10-14 Expires: 2026-10-14 Page title: Home | Golem Trade HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Sectigo Limited / Sectigo Public Server Authentication CA DV R36 Expires: 2026-10-14 Status: INVALID chain Fingerprint: 7a7635bca69bc31ef116c346b44ebc4fa928eb7a34c7f72f540e452faf146959 Subject Alternative Names (related infrastructure — often same operator): - www.golemtrade.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-10-14 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 06:26:45 UTC (by PhishDestroy tracker) First reported: 2026-07-27 07:03:07 UTC (abuse notice filed) Last verified: 2026-07-29 00:20:29 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa2aa-43b0-737c-ad2c-8916b7ef3866/ URLQuery: https://urlquery.net/report/23ecfe0b-5ea3-44e5-9de3-52f0a6293ece Wayback Machine: https://web.archive.org/web/*/golemtrade.com crt.sh CT logs: https://crt.sh/?q=%25.golemtrade.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=golemtrade.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/golemtrade.com URLhaus: https://urlhaus.abuse.ch/host/golemtrade.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 06:29:29 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] golemtrade.com: Confirmed Phishing Site The domain golemtrade.com was registered on 14 October 2025 through Namecheap Inc and is hosted on the IP address 209.74.67.97, which is served by the name servers dns1.namecheaphosting.com and dns2.namecheaphosting.com. Since its creation the domain has appeared on a single public blocklist and is currently listed as active by the monitoring platform. Google Safe Browsing has classified the site under the "social engineering" category, indicating that the URL is being used to lure users into divulging credentials or personal information. Independent analysis on VirusTotal shows that eight out of ninety-one antivirus and URL-reputation engines return a malicious verdict, reinforcing the suspicion of phishing activity. The domain is also flagged by the PhishDestroy blocklist, which specializes in known phishing infrastructure. The available evidence does not include a publicly disclosed page title, SSL certificate details, or HTTP response codes, so the exact content served by the site remains unverified. No additional intelligence such as observed payloads, campaign identifiers, or victim reports has been released. Consequently, while the presence on Google Safe Browsing and multiple security vendor detections provides strong indication of malicious intent, the precise phishing vector and targeted brand cannot be confirmed at this time. Defenders should block any outbound connections to 209.74.67.97 and add golemtrade.com to deny-list rules across DNS resolvers, firewalls, and web proxies. Monitoring of Namecheap-registered domains that resolve to the same IP address may reveal further related infrastructure. Organizations are advised to educate users about unsolicited communications that reference "golemtrade" or similar terminology, and to enforce multi-factor authentication to mitigate credential compromise should a user inadvertently interact with the site. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-03C389 TLS cert SHA-256: 7a7635bca69bc31ef116c346b44ebc4fa928eb7a34c7f72f540e452faf146959 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/golemtrade.com/ JSON API: https://api.destroy.tools/v1/check?domain=golemtrade.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 208,142 domains (82,998 alive under monitoring, 124,112 confirmed takedowns/dead). Site: https://phishdestroy.io