duplicate-disabled-220020.invalid
“Home flywayslogictics - Transportation & Logistics solution enterprise”
www.ontrackcargologistics.com was observed on July 12, 2026 as part of a high‑risk generic phishing campaign.
The detailed PhishDestroy AI analysis below remains in English to preserve the original forensic record.
Evidence Summary
www.ontrackcargologistics.com was observed on July 12, 2026 as part of a high‑risk generic phishing campaign. The site presents a landing page titled “Home flywayslogictics – Transportation & Logistics solution enterprise”, a deliberate attempt to mimic a legitimate logistics provider and lure users into divulging credentials.
The domain was created on May 20, 2026 through NameSilo, LLC. DNS resolution points to 198.251.84.200, a server located in Luxembourg and attributed to FranTech Solutions. Authoritative name servers are ns5.asurahosting.com and ns6.asurahosting.com. The site is protected by an automatically issued Let’s Encrypt certificate (R13) and returns an HTTP 302 status, a common pattern for redirecting victims to credential‑collection pages.
Threat intelligence shows the domain listed on the PhishDestroy blocklist, and VirusTotal records two of ninety‑five scanners flagging the host as malicious. Gridinsoft assigns a trust score of 29 / 100, reinforcing the low confidence in the site’s legitimacy. The page title and branding suggest a targeted impersonation of a logistics service, yet no additional malicious scripts or payloads were observed in the current snapshot, leaving the exact harvesting mechanism uncertain.
Defenders should add www.ontrackcargologistics.com to URL filtering and endpoint deny lists, monitor DNS queries for the associated nameservers, and consider sinkholing the IP address to disrupt traffic. Continuous re‑scanning is recommended, as the low trust score and early detection stage indicate the campaign could evolve to include credential‑stealing forms or malware delivery. Incident response teams should also capture any submitted credentials and correlate them with existing breach data to assess potential impact.
Security Signals
Network Security Intelligence Registrar context
Forensic History & Detection Timeline
-
Domain Status Transition Sep 25, 2026 · 03:31 UTCDomain state transitioned from alive to dead.
Threat Response Pipeline
Public Blocklist Status
Detection-evasion analysis
Cloaking and traffic-distribution check
Not observed
No cloaking was observed in the stored scan
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not observed
- Cloaking score
- 0/6
- Last cloaking scan
Scanner note: dns_error: raw=dns_error; via=local_dns_prefilter
Stored Capture · 1 source
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive