# PhishDestroy threat dossier — primeinvestfx.com ================================================================ Fetched: 2026-07-29 15:05:07 UTC Canonical: https://phishdestroy.io/domain/primeinvestfx.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Fake Exchange Targeted brand: Investment Scam ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 3/91 security vendors flagged this domain Flagging vendors: CRDF, Gridinsoft, SOCRadar AlienVault OTX: 3 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 92.113.23.195 (DE, Frankfurt am Main) ASN: AS47583 Hostinger International Limited Hosting org: HOSTINGER DE Registrar: HOSTINGER operations, UAB Nameservers: ns1.dns-parking.com, ns2.dns-parking.com Registered: 2024-11-09 Expires: 2027-11-09 Page title: Online Trading Platforms | CFDs and Forex Markets | Prime Invest HTTP response: 403 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE2 Expires: 2026-09-30 Status: INVALID chain Fingerprint: c646f7ead7297719f5722c04b3f0019fc77f4e3a102018a6d19a0238bb7f0efc Subject Alternative Names (related infrastructure — often same operator): - www.primeinvestfx.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2024-11-09 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 11:52:41 UTC (by PhishDestroy tracker) First reported: 2026-07-27 14:17:57 UTC (abuse notice filed) Last verified: 2026-07-29 16:20:24 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa2fd-6044-725a-acb0-37dfd23ecfb6/ URLQuery: https://urlquery.net/report/a5da3417-bdcc-42ce-b5f0-e16841c448ce Wayback Machine: https://web.archive.org/web/*/primeinvestfx.com crt.sh CT logs: https://crt.sh/?q=%25.primeinvestfx.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=primeinvestfx.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/primeinvestfx.com URLhaus: https://urlhaus.abuse.ch/host/primeinvestfx.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 11:52:56 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is primeinvestfx.com a phishing site? The domain primeinvestfx.com was registered on 09 November 2024 through the registrar HOSTINGER operations, UAB. DNS resolution points to the address 92.113.23.195 and the authoritative name servers are ns1.dns-parking.com and ns2.dns-parking.com, which are commonly associated with parking services rather than dedicated hosting. The domain appears on a single public blocklist; it is listed by PhishDestroy as a malicious entry and remains active as of the report date, 27 July 2026. VirusTotal records indicate that the domain was submitted for analysis and examined by 91 scanning engines, none of which generated a detection at the time of scanning. While the lack of detections does not constitute evidence of benign intent, it does demonstrate that automated signatures have not yet identified known malicious payloads tied to this host. The combination of a relatively recent registration date, use of generic parking name servers, and inclusion on a phishing‑specific blocklist suggests that the domain is being leveraged for a generic phishing campaign, consistent with the threat classification provided. However, without direct observation of the hosted content, the exact phishing vector, target brand, or credential‑stealing mechanisms cannot be confirmed. Defenders should block network connections to 92.113.23.195 and add primeinvestfx.com to local deny lists. Monitoring for any future changes in DNS records, additional blocklist listings, or the emergence of detections from sandbox or endpoint products is recommended. Organizations employing email filtering should treat any messages referencing primeinvestfx.com as suspicious and apply quarantine or reject policies until further verification is possible. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-FB367F TLS cert SHA-256: c646f7ead7297719f5722c04b3f0019fc77f4e3a102018a6d19a0238bb7f0efc ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/primeinvestfx.com/ JSON API: https://api.destroy.tools/v1/check?domain=primeinvestfx.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,484 domains (83,251 alive under monitoring, 109,716 confirmed takedowns/dead). Site: https://phishdestroy.io