# PhishDestroy threat dossier — invitetracks.top ================================================================ Fetched: 2026-05-10 10:16:25 UTC Canonical: https://phishdestroy.io/domain/invitetracks.top/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 67/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 4/92 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, Google Safebrowsing, Kaspersky ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.97.3 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: CloudFlare, Inc. Registrar: Global Domain Group LLC Nameservers: ["huxley.ns.cloudflare.com.", "ligia.ns.cloudflare.com."] Registered: 2026-05-09 Page title: Telegram: Join Group Chat HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E7 Expires: 2026-08-06 Status: INVALID chain Fingerprint: 7d32e7523e76e695ca0965c074c237ae3d1a0145f2fd355756023bfe8e2ad6f4 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-09 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-09 20:42:03 UTC (by PhishDestroy tracker) Last verified: 2026-05-10 09:33:54 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e0dd1-4b50-70a1-92d6-b026b4d29d80/ Wayback Machine: https://web.archive.org/web/*/invitetracks.top crt.sh CT logs: https://crt.sh/?q=%25.invitetracks.top Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=invitetracks.top AlienVault OTX: https://otx.alienvault.com/indicator/domain/invitetracks.top URLhaus: https://urlhaus.abuse.ch/host/invitetracks.top/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-09 20:43:06 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies invitetracks.top as an active credential theft phishing domain leveraging brand impersonation tactics to harvest user credentials. The domain mimics legitimate invitation or tracking services, likely targeting unsuspecting users into entering login details or personal information into a fraudulent interface. No specific drainer kit or targeted brand has been confirmed in open-source intelligence, but the domain’s structure and naming convention suggest a broad, opportunistic campaign aimed at credential harvesting rather than crypto draining or financial fraud specifically. The operational goal appears to be the aggregation of compromised login credentials for potential resale on dark web markets or immediate exploitation in follow-on attacks such as account takeover or spear-phishing campaigns. This domain was flagged with the following technical indicators: 0 detections out of 95 on VirusTotal as of the latest scan, registered through Global Domain Group LLC, resolving to IP address 188.114.97.3, created on May 08, 2026, secured with a Let’s Encrypt SSL certificate, and currently unlisted in Google Safe Browsing (GSB) and major blocklists (0 blocklist detections recorded). The domain’s recent creation date and pristine detection score indicate it is either newly deployed or carefully crafted to evade initial detection by automated security tools. The use of Let’s Encrypt suggests an attempt to build user trust by providing a valid SSL certificate, a common tactic in phishing campaigns to appear legitimate. As of this report, invitetracks.top remains active and under investigation with a status classified as high risk pending deeper forensic analysis. The lack of immediate detection by security engines and absence from blocklists increase the likelihood of successful user deception. Security teams and end users are strongly advised to block this domain at the network and endpoint levels. Users who may have interacted with the domain are urged to change passwords immediately, enable multi-factor authentication where possible, and scan for credential leaks. Remaining risk is assessed as elevated due to the domain’s active status and the potential for delayed detection by automated systems. Continuous monitoring and community reporting are critical to mitigate ongoing exposure. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 295ccdb03006b8dfef45090dafbd46ac TLS cert SHA-256: 7d32e7523e76e695ca0965c074c237ae3d1a0145f2fd355756023bfe8e2ad6f4 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/invitetracks.top/ JSON API: https://api.destroy.tools/v1/check?domain=invitetracks.top Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 147,757 domains (45,752 alive under monitoring, 101,730 confirmed takedowns/dead). Site: https://phishdestroy.io