# PhishDestroy threat dossier — metadao-dex.com ================================================================ Fetched: 2026-07-30 19:43:31 UTC Canonical: https://phishdestroy.io/domain/metadao-dex.com/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 72/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Solana (and: arbitrum, backpack, base, bnb chain, compound) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 5/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, CRDF, G-Data, Gridinsoft, Sophos Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 186.2.175.109 (BZ, Belmopan) ASN: AS59692 IQWeb FZ-LLC Hosting org: Iqweb LLC Registrar: Fewmoretaps OU d/b/a Trustname.com !!! REGISTRAR INTEGRITY ALERT — Trustname / Fewmoretaps OU !!! Trustname (IANA #4318) is a shell company declaring EUR 120 annual revenue, 1 employee, negative equity, Belarusian ownership. Explicitly advertises itself as 'bulletproof' in its DNS TXT records. Primary source: https://phishdestroy.io/trustname-bulletproof-exposed Nameservers: ares.trustname.com, ns1.anycastdns.cz, ns2.anycastdns.cz, zeus.trustname.com Registered: 2026-07-22 Expires: 2027-07-22 Page title: MetaDAO DEX — #1 Exchange Protocol on Solana | Swap, Bridge, Pool ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-10-20 Status: INVALID chain Fingerprint: d69fe0c5948ea1f575216763c147e5960005a33fc5c7fee6633db3ecc541f4d9 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-22 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-30 16:04:21 UTC (by PhishDestroy tracker) First reported: 2026-07-30 14:20:09 UTC (abuse notice filed) Last verified: 2026-07-30 20:20:19 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fb35f-175d-714b-b8b8-5fdc2d315e46/ URLQuery: https://urlquery.net/report/04e86909-eb0c-4b3c-bd62-dcff13e07f22 Wayback Machine: https://web.archive.org/web/*/metadao-dex.com crt.sh CT logs: https://crt.sh/?q=%25.metadao-dex.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=metadao-dex.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/metadao-dex.com URLhaus: https://urlhaus.abuse.ch/host/metadao-dex.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-30 16:04:41 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] metadao-dex.com Safety Check — Phishing Detected The domain metadao-dex.com was registered on July 22 2026 through Fewmoretaps OU d/b/a Trustname.com. It resolves to the IPv4 address 186.2.175.109 and is served by four authoritative name servers – ares.trustname.com, zeus.trustname.com, ns1.anycastdns.cz, and ns2.anycastdns.cz. VirusTotal records show that five of ninety‑one scanned security vendors flagged the domain, indicating a non‑trivial detection rate among automated scanners. The domain is listed on a single public blocklist and is actively blocked by the PhishDestroy service, reinforcing the view that it is being used for malicious purposes. No additional public intelligence such as Safe Browsing verdicts, Open Threat Exchange reports, SSL certificate details, HTTP response codes, or page‑title information is currently available, so the exact content and targeted brand remain unverified. Analysis of the infrastructure suggests a short‑lived registration coupled with the use of Anycast DNS providers, a pattern frequently observed in phishing campaigns that aim to evade takedown efforts. The presence of multiple trust‑named name servers may indicate an attempt to lend legitimacy to the domain, while the IP address 186.2.175.109 is not associated with a well‑known hosting provider in public records, limiting immediate attribution. The five vendor detections and the blocklist entry provide enough confidence to classify the domain as high‑risk for phishing activity, even though the specific victim lure has not been captured. Defenders should add metadao-dex.com to local deny lists, enforce URL filtering, and monitor outbound traffic for connections to 186.2.175.109. Security solutions that integrate VirusTotal or PhishDestroy feeds will already flag the domain, but manual rule sets can reduce latency. Continuous re‑assessment is advised; additional evidence such as page titles, SSL fingerprints, or observed phishing email samples would refine the threat profile and support takedown requests. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260730-D4DBF7 Favicon MD5: 87d55266c8414c30ab082f6f8fe189ab TLS cert SHA-256: d69fe0c5948ea1f575216763c147e5960005a33fc5c7fee6633db3ecc541f4d9 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/metadao-dex.com/ JSON API: https://api.destroy.tools/v1/check?domain=metadao-dex.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,962 domains (83,660 alive under monitoring, 110,042 confirmed takedowns/dead). Site: https://phishdestroy.io