# PhishDestroy threat dossier — foxlineslogistics.com ================================================================ Fetched: 2026-07-29 11:37:04 UTC Canonical: https://phishdestroy.io/domain/foxlineslogistics.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 12/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, ESET, Fortinet, G-Data, Lionic, SOCRadar, Sophos, VIPRE AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 89.163.155.33 (DE, Frankfurt am Main) ASN: AS24961 WIIT AG Hosting org: myLoc managed IT AG Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED !!! REGISTRAR INTEGRITY ALERT — NiceNIC !!! NiceNIC International: over 90% of its registered domains are associated with illegal content; documented systematic abuse-report non-response. Primary sources: https://phishdestroy.io/nicenic-real https://phishdestroy.io/nicenic-verdict Nameservers: ["ns7.privatedns.vip", "ns8.privatedns.vip"] Page title: Fox Lines Logistics – Ship Smarter, Not Harder HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-09-11 Status: INVALID chain Fingerprint: 5043715b60b007e77b98949fb7ba7ba5385a3718bd7f57e034f436349333f072 Subject Alternative Names (related infrastructure — often same operator): - globaltrustunion.com - www.globaltrustunion.com.foxlineslogistics.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-28 16:23:09 UTC (by PhishDestroy tracker) Last verified: 2026-07-29 12:40:27 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 16:24:52 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] foxlineslogistics.com Used for High‑Risk Generic Phishing This domain, foxlineslogistics.com, was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED. Active probing shows the web server returns HTTP 200, indicating the site is reachable. The authoritative name servers are ns7.privatedns.vip and ns8.privatedns.vip, both hosted on the private DNS service often leveraged by malicious operators. VirusTotal analysis reports that 12 of 91 security vendors have flagged the domain as malicious, reinforcing the high‑risk assessment. The domain is listed on a single blocklist, PhishDestroy, which currently blocks the host, yet the domain remains active and continues to resolve. No additional public intelligence such as page title, SSL certificate details, or hosting IP has been disclosed, leaving the full payload and target profile uncertain. Defenders should ingest the domain into existing blocklists, monitor DNS queries for the associated privatedns.vip name servers, and enforce web‑filter rules that deny traffic to foxlineslogistics.com. Continuous re‑scanning on multi‑engine platforms is advised to capture any changes in detection ratios. Given the registration pattern and the modest blocklist presence, the infrastructure may be part of a broader phishing campaign, and threat‑hunting teams should correlate activity against similar domains and look for related C2 infrastructure that uses the same privatedns.vip name servers. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 9df27652a8f81ab7fe075185462712e6 TLS cert SHA-256: 5043715b60b007e77b98949fb7ba7ba5385a3718bd7f57e034f436349333f072 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/foxlineslogistics.com/ JSON API: https://api.destroy.tools/v1/check?domain=foxlineslogistics.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,360 domains (83,086 alive under monitoring, 109,553 confirmed takedowns/dead). Site: https://phishdestroy.io