# PhishDestroy threat dossier — skybridgecargo.online ================================================================ Fetched: 2026-05-01 07:08:42 UTC Canonical: https://phishdestroy.io/domain/skybridgecargo.online/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 51/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 3/94 security vendors flagged this domain ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 163.61.188.7 (US, Staten Island) ASN: AS153568 NEW DHAKA HARDWARE Hosting org: MIT Registrar: Global Domain Group LLC Nameservers: dns1.lytehosting.com, dns2.lytehosting.com, dns3.lytehosting.com, dns4.lytehosting.com, ns1.cprapid.com, ns2.cprapid.com Registered: 2025-10-19 Page title: skybridgecargo - Logistics ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R13 Expires: 2026-07-19 Status: INVALID chain Fingerprint: 95de54f692bd757b40c89ed91bd1fa38527c824e91fac6407a836f25d49a82ad ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-10-19 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-21 00:06:00 UTC (by PhishDestroy tracker) First reported: 2026-04-20 21:06:49 UTC (abuse notice filed) Last verified: 2026-04-23 01:28:10 UTC Neutralised: 2026-04-23 00:28:09 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019dacb5-f354-763a-8c86-56483b3c71cb/ URLQuery: https://urlquery.net/report/2695099e-2539-43b4-934e-bf33fd53b072 Wayback Machine: https://web.archive.org/web/*/skybridgecargo.online crt.sh CT logs: https://crt.sh/?q=%25.skybridgecargo.online Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=skybridgecargo.online AlienVault OTX: https://otx.alienvault.com/indicator/domain/skybridgecargo.online URLhaus: https://urlhaus.abuse.ch/host/skybridgecargo.online/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-21 00:06:30 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Skybridgecargo.online has been identified as a suspected generic phishing domain masquerading as a legitimate logistics platform. The domain is currently engaged in active operations and remains accessible at this time, with ongoing investigations to validate its legitimacy. No confirmed brand impersonation has been detected, but the site’s facade as a cargo and logistics service suggests a deceptive intent aimed at deceiving users seeking freight or shipping solutions. PhishDestroy confirms this domain exhibits multiple indicators of compromise. It was registered on October 19, 2025, through Global Domain Group LLC and resolves to IP address 163.61.188.7. The site utilizes a Let’s Encrypt SSL certificate, which adds a veneer of legitimacy but does not guarantee trustworthiness. At present, 0 out of 95 VirusTotal security vendors have flagged this domain, and it remains absent from known public blocklists, indicating a low but unassessed risk profile. Trust and domain reputation scores on threat intelligence platforms are currently minimal or nonexistent, suggesting either a newly established infrastructure or deliberate obfuscation of origins. Given the active state and absence of detections, caution is strongly advised. Users and organizations are urged to avoid interacting with this domain, especially for any financial transactions or data submission. Network defenders should monitor egress traffic to 163.61.188.7 and consider blocking it at the perimeter. Additionally, any employees or customers suspecting engagement with this site should immediately report potential compromise and conduct a review of any exposed credentials or payment details. Further intelligence will be provided as the investigation progresses. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260420-4C70AD Favicon MD5: 45f902bc2379b3dbf6b51a090a9f1cd2 TLS cert SHA-256: 95de54f692bd757b40c89ed91bd1fa38527c824e91fac6407a836f25d49a82ad ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/skybridgecargo.online/ JSON API: https://api.destroy.tools/v1/check?domain=skybridgecargo.online Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io