# PhishDestroy threat dossier — tr.meritking-sitegiris.com ================================================================ Fetched: 2026-07-31 09:52:45 UTC Canonical: https://phishdestroy.io/domain/tr.meritking-sitegiris.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 6/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, CRDF, Fortinet, Gridinsoft, PhishFort, SOCRadar Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 104.21.13.203 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: Fewmoretaps OU d/b/a Trustname.com !!! REGISTRAR INTEGRITY ALERT — Trustname / Fewmoretaps OU !!! Trustname (IANA #4318) is a shell company declaring EUR 120 annual revenue, 1 employee, negative equity, Belarusian ownership. Explicitly advertises itself as 'bulletproof' in its DNS TXT records. Primary source: https://phishdestroy.io/trustname-bulletproof-exposed Nameservers: stevie.ns.cloudflare.com, wilson.ns.cloudflare.com Registered: 2026-07-03 Expires: 2027-07-03 Page title: Sektör is god man HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-10-01 Status: INVALID chain Fingerprint: 1609566703ad50dbb460bb33800d86224bff81ba62914502dcc9f5566f108bcd Subject Alternative Names (related infrastructure — often same operator): - meritking-sitegiris.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-03 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 08:32:45 UTC (by PhishDestroy tracker) Last verified: 2026-07-31 08:20:25 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa253-d89f-713d-8200-d9d70a63566b/ Wayback Machine: https://web.archive.org/web/*/tr.meritking-sitegiris.com crt.sh CT logs: https://crt.sh/?q=%25.tr.meritking-sitegiris.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=tr.meritking-sitegiris.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/tr.meritking-sitegiris.com URLhaus: https://urlhaus.abuse.ch/host/tr.meritking-sitegiris.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 08:34:52 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] tr.meritking-sitegiris.com used in high‑risk phishing The domain tr.meritking-sitegiris.com was registered on July 03, 2026 through Fewmoretaps OU d/b/a Trustname.com and remains active as of the report date, July 27, 2026. Infrastructure analysis shows the domain is hosted on Cloudflare’s network, using the authoritative nameservers stevie.ns.cloudflare.com and wilson.ns.cloudflare.com, and resolves to the IP address 104.21.13.203. The domain is listed on at least one public security blocklist and has been explicitly blocked by the PhishDestroy sinkhole, indicating that it is already recognized by threat‑mitigation services. VirusTotal scans have recorded detections from two of ninety‑one security vendors, confirming that a minority of automated scanners have identified malicious characteristics, though the majority have not flagged the domain. No additional public data such as SSL certificate details, HTTP response codes, page titles, or Safe Browsing verdicts are available, leaving the content and exact phishing lure unknown. Consequently, defenders should treat the domain as a high‑risk indicator. Recommended actions include adding the domain and its resolving IP to outbound and inbound firewall deny lists, updating DNS filtering policies to block the associated Cloudflare nameservers, and monitoring for any traffic or authentication attempts to the domain. Organizations should also query threat‑intelligence platforms for any emerging indicators of compromise that reference tr.meritking-sitegiris.com, and consider sharing observed activity with community blocklists to improve collective detection. Continuous re‑evaluation is advised, as further analysis (e.g., page content retrieval, SSL fingerprinting, or sandbox execution) may reveal additional tactics, techniques, and procedures used by the actors behind this infrastructure. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: bdd44821f6ab42b322979ebca9f1a38e TLS cert SHA-256: 1609566703ad50dbb460bb33800d86224bff81ba62914502dcc9f5566f108bcd ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/tr.meritking-sitegiris.com/ JSON API: https://api.destroy.tools/v1/check?domain=tr.meritking-sitegiris.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 196,255 domains (84,241 alive under monitoring, 27,268 confirmed neutralized). Site: https://phishdestroy.io