# PhishDestroy threat dossier β€” mettum-muskk0logiii.godaddysites.com ================================================================ Fetched: 2026-07-25 08:57:06 UTC Canonical: https://phishdestroy.io/domain/mettum-muskk0logiii.godaddysites.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT β€” DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring β€” see methodology below) Scam classification: Credential Phishing ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 18/94 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, Emsisoft, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Kaspersky, LevelBlue, Lionic, MalwareURL, Netcraft, OpenPhish, Sophos, URLQuery, VIPRE, Webroot, Yandex Safebrowsing URLQuery: -1 detections Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 76.223.105.230 (US, Seattle) ASN: AS16509 Amazon.com, Inc. Hosting org: AWS Global Accelerator (GLOBAL) Registrar: GoDaddy Sites Registered: 2026-03-25 Page title: 𝕄𝕖π•₯π•’π“Άπ•’π•€π•œ π•ƒπ• π•˜π•šπ•Ÿ | π•Šπ•šπ•˜π•Ÿ π•€π•Ÿ HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: GoDaddy.com / GoDaddy TLS Intermediate CA DV - R1v1 Expires: 2027-01-09 Status: INVALID chain Fingerprint: 7f80729c4263c741db3e1303d1b17b7cb02c982559aba2db01572e698dffabfc Subject Alternative Names (related infrastructure β€” often same operator): - godaddysites.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet β€” this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-03-25 (per WHOIS / CT β€” may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-03-25 18:30:06 UTC (by PhishDestroy tracker) First reported: 2026-06-15 00:27:29 UTC (abuse notice filed) Last verified: 2026-07-25 04:01:15 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-25 23:05:18 UTC β€” narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] mettum-muskk0logiii.godaddysites.com: Fake Login Portal Detected This domain, mettum-muskk0logiii.godaddysites.com, is identified as a generic phishing infrastructure designed to mimic legitimate login portals. Analysis indicates the site likely employed credential harvesting tactics, though no specific brand impersonation or cryptocurrency drainer kit signatures have been confirmed. The absence of a known brand association suggests a broad-target approach, possibly leveraging social engineering to deceive users into submitting sensitive credentials. Infrastructure analysis reveals the domain was registered on March 25, 2026, through GoDaddy Sites, a platform frequently exploited for low-cost, disposable phishing pages. At its peak, the domain was flagged by 18 out of 95 security vendors on VirusTotal, while Google Safe Browsing (GSB) did not list it at the time of assessment. The domain appeared on a single security blocklist, indicating limited but targeted detection efforts. No associated IP address was retained in available telemetry, suggesting the use of ephemeral hosting or rapid takedowns to evade tracking. The domain is currently offline, likely following enforcement action by the registrar or hosting provider. However, the elevated risk persists due to the domain's recent creation and prior malicious activity. Users who may have interacted with the site are advised to rotate credentials immediately, particularly for accounts accessed during the domain's active period. Organizations should monitor for credential-stuffing attempts using harvested data and consider proactive blocklisting of the domain in security controls. The short lifespan of such domains underscores the need for real-time threat intelligence and automated response mechanisms to mitigate similar threats. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 515f6b602beb3e9792bb5dcb0b74050b TLS cert SHA-256: 7f80729c4263c741db3e1303d1b17b7cb02c982559aba2db01572e698dffabfc ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe β€” new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/mettum-muskk0logiii.godaddysites.com/ JSON API: https://api.destroy.tools/v1/check?domain=mettum-muskk0logiii.godaddysites.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 189,489 domains (59,800 alive under monitoring, 128,126 confirmed takedowns/dead). Site: https://phishdestroy.io