# PhishDestroy threat dossier — gotruckdelivery.com ================================================================ Fetched: 2026-07-26 05:58:55 UTC Canonical: https://phishdestroy.io/domain/gotruckdelivery.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 82/100 (PhishDestroy scoring — see methodology below) Scam classification: Crypto Scam Targeted brand: across (and: scroll) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 14/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Lionic, SOCRadar, Sophos, VIPRE, Webroot URLQuery: 2 detections Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 192.142.54.88 (NL, Amsterdam) ASN: ASAS214036 ULTAHOST-AS Ultahost, Inc., US Hosting org: AS214036 Ultahost, Inc. Registrar: TuringSign Inc. d/b/a Cosmotown Nameservers: ["ns1.hostcreed.com", "ns2.hostcreed.com"] Registered: 2026-03-11 Page title: Welcome to GoTruck Delivery Company - Premium Global Shipping Solutions HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R13 Expires: 2026-06-02 Status: INVALID chain Fingerprint: 14aff3748f1ec663846ac122ab314157484c28a095cdb2e2cf64e4876422ab85 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-03-11 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-03-11 05:00:27 UTC (by PhishDestroy tracker) Earliest abuse rec: 2026-03-11 02:29:53 UTC — PREDATES current WHOIS registration; retained from a previous registration cycle of the same domain name Last verified: 2026-07-26 04:21:01 UTC Current status: ACTIVE / observable Note: one or more events above predate the WHOIS creation date. This typically means the same domain name was previously registered, detected, dropped, and then re-registered by a new party. PhishDestroy preserves the full historical record for operator-attribution research even when the underlying infrastructure changes hands. ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019cda9d-2d9e-759e-bb7e-60a75ea2029d/ URLQuery: https://urlquery.net/report/595288ee-80a3-4a5d-9425-da599b3ac897 Wayback Machine: https://web.archive.org/web/*/gotruckdelivery.com crt.sh CT logs: https://crt.sh/?q=%25.gotruckdelivery.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=gotruckdelivery.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/gotruckdelivery.com URLhaus: https://urlhaus.abuse.ch/host/gotruckdelivery.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-13 00:41:08 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] gotruckdelivery.com brand impersonation crypto scam warning The domain gotruckdelivery.com was registered on March 11, 2026 and is currently active. DNS analysis shows MX records pointing to the domain itself with priority 0 and authoritative name servers ns1.hostcreed.com and ns2.hostcreed.com. The domain resolves to IP 192.142.54.88, which belongs to AS214036 Ultahost, Inc. in the Netherlands. An SSL certificate issued by Let’s Encrypt (R13) is present, and the web server responds with HTTP 200, delivering content built with PHP, Tailwind CSS, LiteSpeed, Alpine.js, and external libraries from Unpkg and jsDelivr over HTTP/3. The page title "Welcome to GoTruck Delivery Company - Premium Global Shipping Solutions" suggests a logistics theme, while the intelligence tags identify the site as a brand-impersonation campaign targeting the "across" brand and operating as a crypto scam. VirusTotal scans show 14 of 95 security vendors flagging the domain, and the site appears on a single security blocklist. PhishDestroy has already blocked the domain, and Gridinsoft assigns a trust score of 0/100, indicating high risk. Registration details list TuringSign Inc. d/b/a Cosmotown as the registrar. While the exact malicious payload and victim interaction flow remain unknown, the combination of recent registration, low trust score, vendor detections, and confirmed blocklist placement signals a high‑confidence threat. Defenders should add the domain to outbound and inbound filtering rules, monitor DNS queries for the associated IP and name servers, and consider broader threat‑intel sharing to prevent credential or crypto‑asset theft attempts linked to this impersonation campaign. [Updates since narrative was generated:] - VirusTotal detections: now 14/91 (narrative was written when count was lower) ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260311-BCC1F8 Favicon MD5: 75cd49c8f64829d2c0c6444b4d1d628c TLS cert SHA-256: 14aff3748f1ec663846ac122ab314157484c28a095cdb2e2cf64e4876422ab85 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/gotruckdelivery.com/ JSON API: https://api.destroy.tools/v1/check?domain=gotruckdelivery.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,604 domains (65,238 alive under monitoring, 128,816 confirmed takedowns/dead). Site: https://phishdestroy.io