# meridiancapitalholdings.carrd.co — SUSPICIOUS > meridiancapitalholdings.carrd.co is a crypto drainer impersonating Meridian Capital Holdings. Avoid this domain; verify on PhishDestroy for safety. ## Summary PhishDestroy identifies meridiancapitalholdings.carrd.co as a generic phishing domain currently under active investigation for potential crypto drainer activity. The domain mimics legitimate financial entities to deceive users into transferring cryptocurrency to attacker-controlled wallets. Current telemetry suggests this is a high-effort impersonation targeting individuals or organizations engaged in financial services or investments. This domain was flagged by 0 of 95 VirusTotal vendors as of the latest scan, indicating it remains undetected by most antivirus engines despite its malicious intent. The domain resolves to IP address 104.18.40.34, which is associated with Cloudflare infrastructure, a common hosting provider for malicious sites due to its anonymity features. The domain was registered recently and currently shows no presence on major threat intelligence blocklists, though its SSL certificate is issued by Google Trust Services, a tactic often used to lend false legitimacy to phishing pages. Trust scores for the domain remain neutral at this time, but behavioral analysis suggests elevated risk. Investigation into this domain is ongoing, but preliminary indicators warrant caution. Users are advised to avoid interacting with meridiancapitalholdings.carrd.co or any associated links, especially those claiming to offer financial services or crypto-related opportunities. Verify the legitimacy of any financial platform through official channels before engaging. Security teams should monitor traffic to 104.18.40.34 and consider blocking this IP if malicious activity is confirmed. PhishDestroy will update this advisory as new intelligence emerges. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: REGISTRAR_NOT_FOUND - IP: 104.18.40.34 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/domains/meridiancapitalholdings.carrd.co - PhishDestroy: https://phishdestroy.io/domain/meridiancapitalholdings.carrd.co/ - LLM endpoint: https://phishdestroy.io/domain/meridiancapitalholdings.carrd.co/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/meridiancapitalholdings.carrd.co/ Last updated: 2026-04-04