This company has verified ownership of the profile and can respond to reviews.
Phishing
This site is classified as Phishing based on multiple risk signals, including 1 blacklist detections, no established public user-review history, and phishing-related signals. These risks are driven by active warning signals despite the site's longer domain history.
checkout-targeted third-party script loader is present
the injected loader persisted across archived and current pages
Context signals:
content related to online shopping and ecommerce; educational content and guides
Last checked October 1, 2026 at 10:48 PM by
Gridinsoft Trust Model v2.5.5
Share this report?
Independent Gridinsoft analysis
What Gridinsoft observed on goldmountaingolf.com
A Gridinsoft threat analyst reviewed the site directly and documented the evidence behind this decision.
Current review
Review ID
GMA-20260903025100-d840ea64
Reviewed
by Gridinsoft Threat Analyst
Analyst finding
Phishing
Evidence basis
First-party site analysisExternal vendor intelligence: Context only — not used for this decision
The legitimate golf-course content does not make this request a false positive. A checkout-targeted loader capable of injecting third-party JavaScript into a live card-payment form is directly reproducible and has persisted in archived and current pages. The existing Phishing classification is retained. The unavailable second-stage endpoint limits claims about the payload currently delivered, but does not negate the site-code compromise.
Analyst findings
High2
Info1
High01
Checkout-targeted third-party script loader is present
The live site contains injected code that can add remotely supplied JavaScript to a checkout page that collects payment-card details. This is a reproducible site compromise and supports retaining the Phishing classification independently of external blacklist labels.
Info02
The current second-stage payload was not retrievable
The configured external endpoint was NXDOMAIN during the review, so no specific second-stage file, script URL, payload hash, or observed card-data transmission is claimed. The harmful finding is the persistent checkout-targeted loader itself.
High03
The injected loader persisted across archived and current pages
The loader was absent in the reviewed July 2025 snapshot, appeared by October 2025, remained visible in later archived snapshots, and is still present on the current site. This persistence indicates that the compromise has not been removed from the served page code.
Review 5 documented observations
View evidence
01HTTP response
The reviewed site presented the expected Gold Mountain Golf Club content. Its public sitemap exposed normal golf, restaurant, event, store, cart, and checkout routes; no unrelated automatic top-level redirect or executable download was reproduced in the reviewed navigation.
HTTP status200
Final URLhttps://goldmountaingolf.com/
Analyst observationThe visible operator content is consistent with a golf-course and hospitality website, but that legitimate presentation does not remove the separate checkout code compromise.
02Content
A script element identified as gli0 was present in the live site footer. It checks whether the browser path contains checkout, sends a POST request to https://brisca.sbs/, decodes the response as a JavaScript source URL, and adds that external script to the page. The same injected loader was reproduced on ordinary pages, while its conditional behavior targets the checkout path.
Page elementscript element id gli0
Public artifact URLhttps://brisca.sbs/
Analyst observationThe loader dynamically adds a third-party JavaScript source only when the current pathname includes checkout.
03Form
After adding a currently listed product to a temporary cart, the checkout returned HTTP 200 and displayed fields for the card number, expiration month and year, and card security code. The checkout-targeted external loader was present in that same response.
The external loader endpoint returned DNS NXDOMAIN from two independent network locations. No payload URL, payload bytes, file hash, credential submission, or card-data transmission could therefore be retrieved or observed during this review.
DNS factbrisca.sbs returned NXDOMAIN for A, AAAA, and NS queries
Analyst observationNo current second-stage script or payload hash was available for analysis.
05Historical content
Archived homepage snapshots from 2017, 2019, 2022, January 2025, and July 2, 2025 did not contain the gli0 loader. A snapshot from October 11, 2025 contained the same checkout-targeted loader and https://brisca.sbs/ endpoint, as did later reviewed snapshots from November 2025 and May and June 2026.
Public artifact URLhttps://web.archive.org/web/20250702200013/https://goldmountaingolf.com/
Public artifact URLhttps://web.archive.org/web/20251011153447/https://goldmountaingolf.com/
Analyst observationThe reviewed archive establishes introduction between July 2 and October 11, 2025 and persistence into the current site; it does not establish when the unavailable second stage was active.
Scope and limitations
The exact second-stage payload could not be retrieved because brisca.sbs returned NXDOMAIN during the review.
No completed payment or real card data was submitted; the checkout was reviewed with a temporary cart and without placing an order.
The archive timeline establishes when the loader was absent and present in reviewed snapshots, not the complete activation history of the remote payload.
The result applies to the domain and public checkout behavior observed at the recorded time; remediation requires removal of the injected code and a fresh exact-flow review.
What is Goldmountaingolf?
We flagged Goldmountaingolf.com as phishing. The page behavior matches a common credential-theft flow: impersonation first, urgency second, data request last.
Typical prompts on sites like this include account alerts, failed-delivery notices, or "verify now" dialogs asking for passwords, card numbers, or one-time codes. Do not submit credentials here. Open the real service in a new tab and check your account directly.
This domain was registered December 31, 2012 at 9:43 PM through the company GoDaddy.com, LLC
WHOIS registrant details are private. Separately, the business has verified control of its Gridinsoft profile.
🚨
Gridinsoft blocks this website because it was classified as phishing.
goldmountaingolf.com should not be treated as a safe website. Gridinsoft gives it a 10/100 trust score, and publicly displayed security sources report 1 warning(s). Avoid entering passwords, personal details, or payment data.
Why is goldmountaingolf.com marked "Phishing"?
Gridinsoft evaluates goldmountaingolf.com, focusing on limited website popularity, suspicious content indicators (Blacklisted by Security Providers, Heuristic - Phishing, Heuristic Risk), hosting technology and infrastructure, SSL certificate status, website reputation across multiple databases, customer reviews from various independent platforms. We weigh these indicators to calculate the trust score.
Note: Automated systems are not perfect — while the evidence suggests risk, there is still a chance the site is legitimate. We recommend you check the website using detailed analysis or by contacting the company directly through verified channels.
A structured view of the site's detected themes, page signals, and related online footprint elements.
Registration Form
Automated page analysis detected form or data-entry functionality on goldmountaingolf.com. Forms can involve user-submitted information, so verify ownership and privacy terms before entering data.
Shopping
This site shows e-commerce functionality, including product listings, cart flow, and checkout-related elements.
Education
Clothing
Cookie Consent
goldmountaingolf.com implements a cookie-consent interface for managing tracking and data-collection preferences.
Uses Free eCommerce Engine
This website utilizes free e-commerce platform solutions, which may indicate cost-conscious operations but could also suggest limitations in security features, customer support, or advanced functionality compared to enterprise-grade solutions.
Wordpress Platform
Our analyzer determines that this website is using WordPress CMS. WordPress is the most popular content management system, powering over 43% of websites globally.
Android App
The goldmountaingolf.com website offers a mobile application for Android devices, indicating expanded platform presence beyond web-based services.
Apple App
This website has an iOS mobile application available, indicating cross-platform accessibility for Apple device users.
Google Tag Manager
This website uses Google Tag Manager to add and update tracking tags on its website.
Meta Verified
This website is linked to a verified entity on Meta's platforms, helping to reduce the risk of impersonation or fraud.
Cloudflare Browser Insights
This website is proxied through Cloudflare's CDN/network and has Cloudflare Browser Insights enabled.
SEO Optimization
This website employs search engine optimization (SEO) techniques to improve its visibility and ranking in search engine results pages (SERPs).
Google Maps
Facebook Integration
jQuery Library
Social Media Links
The presence of social media links on the website indicates that it references social media accounts. This signal alone does not confirm ownership or authenticity of those profiles.
Blacklisted by Security Providers
Security intelligence signal: A security-provider signal contributes to the automated assessment of goldmountaingolf.com. Publicly displayable provider verdicts, when available, are reported separately; some source details may be restricted by license.
AI-generated Text
This site contains text patterns consistent with machine-generated or AI-assisted content production.
Heuristic - Phishing
Heuristic Risk
Established Domain
goldmountaingolf.com has maintained active domain presence over time, indicating operational continuity.
Listed by Gridinsoft
Gridinsoft Internet Security classified this site as unsafe. As a VirusTotal partner, our detections contribute to broader protection across tools and browsers.
Claimed Company Profile
The company behind this site has claimed its profile in the Gridinsoft portal and provided verified ownership details.
Verified X Profile
Ownership verification confirms that goldmountaingolf.com controls the X profile @GoldMtGolf (Gold Mountain Golf) (649 followers, 995 following, 1,592 posts, listed 13 times, since 2013, no account badge, location: Bremerton, WA).
External provider warnings: 1/26 Phishing
This section shows what independent external security sources say about this site.
A warning appears when one or more sources report malware, phishing, abuse, or other safety concerns. Each row shows the source and its verdict.
If no source reports a warning, the site is shown as clear in this section.
Fortinet
Malware
External provider results for Goldmountaingolf.com, last checked October 2, 2026.
— VirusTotal
Domain Information
CreatedDecember 31, 2012 at 9:43 PMUpdated: March 12, 2025 at 6:17 PM · Expires: December 31, 2026 at 9:43 PM
Hosting ProviderAS13335 Cloudflare, Inc.San Francisco, California, US
SSL CertificateWE1TLSv1.3 · Valid for: 3 months · from September 12, 2026 at 10:31 PM · to December 11, 2026 at 11:28 PM
Name Serverscarl.ns.cloudflare.com nucum.ns.cloudflare.com
Content from the analyzed website
Quoted for security analysis. These statements belong to the source website and are not endorsed by Gridinsoft.
Original page titleGolf Courses Washington, Gold Mountain Golf Club, Bremerton, WA
Original description36 hole Washington Golf Course located on the Olympic Peninsula in Bremerton, Washington. Weddings, Special Events, Meetings and more.
www.facebook.comwww.google-analytics.comwww.googletagmanager.comad.doubleclick.netconnect.facebook.netwww.pinterest.comnoteefypublic.blob.core.windows.netapps.apple.comfonts.googleapis.comwww.google.comgoldmountaingolf.noteefy.appgmpg.orgstatic.cloudflareinsights.comfonts.gstatic.comwww.ci.bremerton.wa.us
and 9 more
Security Analysis
Detection SignaturesThese signatures are used to generate the security fingerprint below.
Goldmountaingolf.com has a low visibility ranking globally.
Loading...
Signs You're Dealing With an Online Scam
Scammers have devised new ways to deceive users, and what was relevant ten years ago may not be applicable today. In this post, we have compiled the most current types of online scams.
If you own Goldmountaingolf.com and want to challenge the trust score, please submit a review request via portal.gridinsoft.com. There you can claim your profile and add verified company/contact details. If you cannot access the portal, email legal(at)gridinsoft.com with proof of legitimacy and contact details. We never charge website owners for reviews or reconsideration requests. For more information, please review our Disclaimer.
A website report warns you. A PC scan protects you.
Unsafe sites can leave adware, unwanted apps, or hidden malware in downloads and browser settings. Run Gridinsoft Anti-Malware to check what may already be on this Windows PC.
Checks active threats, startup items, and suspicious downloads
Finds adware and unwanted apps linked to unsafe websites
Shows scan results before you decide what to remove
Your comment is currently undergoing moderation and will be published shortly.
Help protect others by sharing this page on social media! The more people who know about goldmountaingolf.com, the fewer chances they have to deceive someone else.Help others evaluate goldmountaingolf.com by sharing this page on social media!
Help protect others by sharing this page on social media! The more people who know about goldmountaingolf.com, the fewer chances they have to deceive someone else. Help others evaluate goldmountaingolf.com by sharing this page on social media!