logisticamericango1directly-t6120[.]roqaproduction[.]com
“href.li”
Analysis of logisticamericango1directly-t6120.roqaproduction.com shows a high‑risk generic phishing infrastructure that remains active as of 19 July 2026. The domain was registered through Wild West Domains, LLC and is delegated to Microsoft‑associated nameservers ns1.bdm.microsoftonline.com and ns2.bdm.microsoftonline.com. HTTP requests receive a 302 redirect, and the TLS certificate is issued by Let’s Encrypt (entity YE1), indicating standard encryption without further validation. The site resolves to 172.86.72.189, an address attributed to a US‑based provider identified as FranTech Solutions. Threat intelligence sources have placed the domain on at least one security blocklist and it is listed by PhishDestroy as blocked. VirusTotal scans report 18 of 91 AV engines flagging the domain, confirming malicious intent. The page title returned by the server is “href.li”, which does not reveal a target brand or credential‑harvesting page and suggests the content has not yet been catalogued. Current evidence confirms the domain’s use for phishing; however, the exact lure, credential‑collection mechanism, and victim profile remain unknown. Defenders should block the domain and its IP at perimeter firewalls, update URL filtering feeds, and monitor for any outbound connections to the 172.86.72.189 address. Continuous re‑scanning with multi‑engine services is advised to capture any changes in payload or hosting.
Threat Response Pipeline
Public Blocklist Status
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Registration: roqaproduction.com
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For the registrable domain roqaproduction.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 8 identified
Bootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
getbootstrap.com 100% confidenceAmazon Web Services (AWS) is a comprehensive cloud services platform offering compute power, database storage, content delivery and other functionality.
aws.amazon.com 100% confidenceApache Traffic Server is an open-source caching and proxying server that serves as an HTTP/1.1 and HTTP/2 reverse proxy with caching capabilities, load balancing, request routing, SSL termination, and support for advanced HTTP features.
trafficserver.apache.org 100% confidencejQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 100% confidenceHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% confidenceAmazon S3 or Amazon Simple Storage Service is a service offered by Amazon Web Services (AWS) that provides object storage through a web service interface.
aws.amazon.com 100% confidenceVirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of logisticamericango1directly-t6120.roqaproduction.com · checked Jul 20, 2026
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive