Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@godaddy.com.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
globalbusinesspays[.]com
“Global Business Pay | E - Wallet”
globalbusinesspays.com — Прикритий · доступний. Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 5/91 (alphaMountain.ai, CRDF, Fortinet, Gridinsoft, Kaspersky); URLQuery 1 alert; cloaking observed; PhishDestroy score 70/100. Реєстратор: GoDaddy.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
globalbusinesspays.com was registered on March 6, 2026 through GoDaddy.com, LLC and is served from the IP address 160.153.0.86. The domain resolves via the default GoDaddy nameservers ns51.domaincontrol.com and ns52.domaincontrol.com and presents a TLS certificate issued by Google Trust Services (WE1). The certificate is valid for the host name and the HTTP response returns status 200, indicating the site is actively delivering content.
The landing page uses the title “Global Business Pay | E - Wallet”, a phrasing commonly employed in fraudulent e‑wallet and cryptocurrency lure campaigns. The page’s visual design mimics legitimate payment platforms and solicits user credentials or cryptocurrency transfers, matching the classified scam type of “cryptocurrency”. No additional legitimate branding is observed, reinforcing the malicious intent.
Reputation data corroborates the malicious assessment. Gridinsoft assigns a trust score of 1 out of 100, and VirusTotal records 1 positive detection out of 95 scanned security vendors. The domain appears on a single public blocklist and is actively listed by PhishDestroy. The risk level is marked high, and the current status is listed as active, indicating ongoing operation.
Defenders should add 160.153.0.86 and the domain globalbusinesspays.com to network deny lists, enforce URL filtering, and monitor DNS queries for the associated GoDaddy nameservers. Email gateways should block inbound messages that reference the e‑wallet terminology and any requests for cryptocurrency payments originating from this host. Incident response teams should collect HTTP traffic samples for further forensic analysis and advise users to avoid providing credentials or funds to the site.
At present, limited forensic artifacts are publicly available; the precise phishing kit or infrastructure reuse patterns have not been disclosed. Continuous monitoring is advised to detect possible expansion to additional domains or changes in hosting.
Сигнали безпеки
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | maps.googleapis.com/maps-api-v3/api/js/64/3a/common.js |
audit | Hunting_JS_WebAssembly |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
PD-20260306-5C4E30 Recipient: abuse@godaddy.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога