# PhishDestroy threat dossier — meta-action.invoice-ads-manager.com ================================================================ Fetched: 2026-05-07 16:23:02 UTC Canonical: https://phishdestroy.io/domain/meta-action.invoice-ads-manager.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 99/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 17/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, ESET, Emsisoft, Fortinet, G-Data, Lionic, Netcraft, Seclookup, Sophos, VIPRE, Webroot URLQuery: 2 detections ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.66.0.96 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: Gransy, s.r.o. Nameservers: ns.gransy.com, ns2.gransy.com, ns3.gransy.com, ns4.gransy.com, ns5.gransy.com Registered: 2026-04-28 Page title: Accounts Centre HTTP response: 403 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-08-02 Status: INVALID chain Fingerprint: 2e0de6830496cf5090d630bcd67b046662b5ab8332f925b84f68628748432b8d ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-28 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-05 03:12:29 UTC (by PhishDestroy tracker) First reported: 2026-05-05 00:13:26 UTC (abuse notice filed) Last verified: 2026-05-06 13:40:17 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019df578-bfbf-71eb-83df-d16dcbe58d23/ URLQuery: https://urlquery.net/report/29b95f39-4eef-4caa-9d52-ed12ac825468 Wayback Machine: https://web.archive.org/web/*/meta-action.invoice-ads-manager.com crt.sh CT logs: https://crt.sh/?q=%25.meta-action.invoice-ads-manager.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=meta-action.invoice-ads-manager.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/meta-action.invoice-ads-manager.com URLhaus: https://urlhaus.abuse.ch/host/meta-action.invoice-ads-manager.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-05 03:14:16 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies meta-action.invoice-ads-manager.com as a high-risk crypto drainer impersonating Meta’s Accounts Centre login portal, likely deployed to harvest credentials and session tokens for wallet compromise. The domain’s page title—Accounts Centre—mirrors Meta’s official branding to deceive visitors into entering login details, which are then exfiltrated to attacker-controlled servers. Although no known drainer kit hash was retrieved during analysis, the page’s structure and naming convention strongly suggest an automated credential theft interface. This domain was flagged by 14 of 95 VirusTotal security vendors and resolves to IP 172.66.0.96 via Google Trust Services SSL. Registered through Gransy, s.r.o. on April 28, 2026, it remains uncategorized by Google Safe Browsing as of the latest scan. These technical indicators confirm a newly activated threat with minimal historical vetting, increasing the likelihood of successful deception. The site remains active and accessible as of this report, posing an ongoing risk to users who may encounter it through phishing emails, fake ads, or compromised ad accounts. PhishDestroy recommends immediate network-level blocking of the domain and IP, user education on verifying login URLs, and scanning of stored browser sessions for unauthorized access. While the domain’s recent creation limits long-term reputation data, its active status and moderate detection rate indicate a rapidly evolving threat requiring urgent mitigation. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260505-D26C62 TLS cert SHA-256: 2e0de6830496cf5090d630bcd67b046662b5ab8332f925b84f68628748432b8d ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/meta-action.invoice-ads-manager.com/ JSON API: https://api.destroy.tools/v1/check?domain=meta-action.invoice-ads-manager.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 146,946 domains (52,762 alive under monitoring, 93,769 confirmed takedowns/dead). Site: https://phishdestroy.io