# PhishDestroy threat dossier — metakingglobals.com ================================================================ Fetched: 2026-07-27 08:16:31 UTC Canonical: https://phishdestroy.io/domain/metakingglobals.com/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 69/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 13/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET, Fortinet, G-Data, Gridinsoft, Kaspersky, Lionic, Sophos, VIPRE AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 185.173.111.99 (BR, São Paulo) ASN: AS47583 Hostinger International Limited Hosting org: Hostinger International Limited Registrar: HOSTINGER operations, UAB Nameservers: ns1.dns-parking.com, ns2.dns-parking.com Registered: 2026-01-29 Expires: 2027-01-29 Page title: MKG- Meta Kings Global ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-08-27 Status: INVALID chain Fingerprint: 999eeb8f5850ded2ef73a0a040832c227d3c7317bf7c0d0bc6d07691078fb4a1 Subject Alternative Names (related infrastructure — often same operator): - www.metakingglobals.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-01-29 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 06:48:17 UTC (by PhishDestroy tracker) First reported: 2026-07-27 07:59:55 UTC (abuse notice filed) Last verified: 2026-07-27 10:15:04 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa1ef-fb0a-7759-8724-12b5eb1c7206/ URLQuery: https://urlquery.net/report/4313d1bc-8345-4d58-a9b3-e29e51055b50 Wayback Machine: https://web.archive.org/web/*/metakingglobals.com crt.sh CT logs: https://crt.sh/?q=%25.metakingglobals.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=metakingglobals.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/metakingglobals.com URLhaus: https://urlhaus.abuse.ch/host/metakingglobals.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 06:52:08 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] metakingglobals.com Safety Check — Meta Kings Global Phishing Analysis of metakingglobals.com indicates a high-risk phishing domain actively targeting users under the guise of 'Meta Kings Global,' as evidenced by the page title 'MKG- Meta Kings Global.' The domain was registered on January 29, 2026, through HOSTINGER operations, UAB, and remains operational as of July 27, 2026. Infrastructure analysis reveals the domain resolves to the IP address 185.173.111.99 and utilizes nameservers ns1.dns-parking.com and ns2.dns-parking.com, a configuration often associated with low-cost or disposable hosting environments commonly exploited for phishing campaigns. Security vendor detections further substantiate the threat: 13 of 91 engines on VirusTotal flag the domain as malicious, and it appears on at least one security blocklist. The domain is currently blocked by PhishDestroy, though it remains accessible, suggesting ongoing malicious activity. No evidence links this domain to legitimate services, and the combination of recent registration, parking-style nameservers, and security vendor detections aligns with patterns observed in phishing infrastructure. Defenders should treat this domain as a confirmed phishing threat. Immediate actions include blocking the domain and its resolving IP (185.173.111.99) at the network perimeter, updating endpoint protection rules, and monitoring for connections to the associated nameservers. The exact nature of the phishing content—such as whether it targets credentials, financial data, or other sensitive information—has not been fully analyzed, but the presence of the 'Meta Kings Global' branding suggests a potential focus on cryptocurrency or metaverse-related scams. Organizations should prioritize user education to recognize such threats, particularly those involving emerging digital asset platforms. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-5C6DF2 Favicon MD5: f96a339d4f01a480f800f48f2da623c9 TLS cert SHA-256: 999eeb8f5850ded2ef73a0a040832c227d3c7317bf7c0d0bc6d07691078fb4a1 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/metakingglobals.com/ JSON API: https://api.destroy.tools/v1/check?domain=metakingglobals.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 204,037 domains (79,459 alive under monitoring, 123,547 confirmed takedowns/dead). Site: https://phishdestroy.io