# PhishDestroy threat dossier — info.fast-shipping.it ================================================================ Fetched: 2026-07-30 10:57:21 UTC Canonical: https://phishdestroy.io/domain/info.fast-shipping.it/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 96/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 7/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, Chong Lua Dao, Cluster25, ESET, Gridinsoft, SOCRadar, URLQuery Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 3.248.19.132 (IE, Dublin) ASN: AS16509 Amazon.com, Inc. Hosting org: AWS EC2 (eu-west-1) Registered: 2026-06-03 HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Sectigo Limited / Sectigo Public Server Authentication CA DV R36 Expires: 2026-12-09 Status: INVALID chain Fingerprint: df26703a3417d02fdf2c50cc144cfddb642e390175edfc29c66d86329c786401 Subject Alternative Names (related infrastructure — often same operator): - fast-shipping.it ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-06-03 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-06-09 05:23:24 UTC (by PhishDestroy tracker) First reported: 2026-06-15 06:46:37 UTC (abuse notice filed) Last verified: 2026-07-30 12:20:55 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-12 17:51:19 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is info.fast-shipping.it a phishing site? info.fast-shipping.it was registered on June 03, 2026 and resolves to the IPv4 address 3.248.19.132, which belongs to an Amazon Web Services EC2 instance in the eu-west-1 region of Ireland. The rapid registration and use of cloud infrastructure are consistent with a short-lived campaign designed to host malicious web content. A direct HTTP request returns status code 200, indicating that a web server is actively serving pages. The site presents a Sectigo Limited / Sectito Public Server Authentication CA DV R36 TLS certificate, a publicly trusted certificate that masks the underlying intent. Reputation checks show the domain on a single security blocklist, a Gridinsoft trust score of 0 out of 100, and seven of ninety-five VirusTotal scanners flagging it as malicious. PhishDestroy also lists the domain as blocked. The content served by the site has not been publicly disclosed, and no specific phishing landing pages or credential-harvesting forms have been captured in open-source feeds. Consequently, the exact branding, lure technique, or victim profile targeted by this domain remain unknown. The limited number of detections suggests either a very recent deployment or a low-volume operation that has not yet been widely shared. Defenders should treat info.fast-shipping.it as a high-risk indicator. Immediate actions include adding the domain and its resolved IP address to outbound allow-list blocks, updating DNS filtering policies, and enabling TLS inspection to intercept any encrypted traffic. Continuous monitoring for new samples, URL redirects, or related domains sharing the same AWS subnet is advised. Incident response teams should also review email logs for any messages referencing “fast‑shipping” or similar phrasing, as the domain name hints at a logistics-related phishing lure. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 19df0d067ad1549ef3c71e9d75787a28 TLS cert SHA-256: df26703a3417d02fdf2c50cc144cfddb642e390175edfc29c66d86329c786401 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/info.fast-shipping.it/ JSON API: https://api.destroy.tools/v1/check?domain=info.fast-shipping.it Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,594 domains (83,321 alive under monitoring, 110,013 confirmed takedowns/dead). Site: https://phishdestroy.io