# PhishDestroy threat dossier — starlightgc.icu ================================================================ Fetched: 2026-04-24 13:13:03 UTC Canonical: https://phishdestroy.io/domain/starlightgc.icu/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 91/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 6/94 security vendors flagged this domain URLQuery: 1 detections ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 37.49.229.75 (NL, Amsterdam) ASN: AS3920 PUSHPKT OU Hosting org: ESTOXY OU Registrar: Global Domain Group LLC Nameservers: ns1.controlpanel.sbs, ns2.controlpanel.sbs Registered: 2026-04-22 Page title: Home - Starlight Global Capital HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-07-22 Status: INVALID chain Fingerprint: 06e2546e1f6051af7b8f624424efada3afbcdd9bfafcc1870378f0f63a6f2451 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-22 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-23 15:18:39 UTC (by PhishDestroy tracker) First reported: 2026-04-23 12:19:38 UTC (abuse notice filed) Last verified: 2026-04-24 13:01:18 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019dba46-1dd8-75ad-a5a3-f296d685156f/ URLQuery: https://urlquery.net/report/4aff962f-aa0e-44b6-bd75-e0cdd413b4a1 Wayback Machine: https://web.archive.org/web/*/starlightgc.icu crt.sh CT logs: https://crt.sh/?q=%25.starlightgc.icu Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=starlightgc.icu AlienVault OTX: https://otx.alienvault.com/indicator/domain/starlightgc.icu URLhaus: https://urlhaus.abuse.ch/host/starlightgc.icu/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-23 15:19:07 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies starlightgc.icu as an active fake-login phishing domain luring users to surrender credentials under deceptive branding. This site is engineered to harvest usernames and passwords in real time. Threat actors rapidly weaponize newly registered domains to masquerade as trusted services, aiming to harvest authentication tokens and initiate account takeovers. The risk to end-users is immediate and severe, as stolen credentials can be reused across multiple platforms, leading to financial loss and identity theft. Technical indicators tie starlightgc.icu to a known infrastructure cluster. The domain resolves to IPv4 address 37.49.229.75, registered on April 22, 2026 through Global Domain Group LLC, and secured with a Let’s Encrypt SSL certificate—all tactics used to appear legitimate. VirusTotal currently shows 0 out of 95 detection engines flagging the domain, indicating it remains under the radar. Despite the lack of antivirus coverage, the domain’s youth and hosting profile suggest a high-risk profile consistent with emerging phishing operations. No blocklist entries are yet visible, but trust scores across domain reputation services are expected to be low due to its recent creation and single-purpose deployment. Mitigation requires immediate action by users and defenders. Avoid visiting or interacting with starlightgc.icu; never input credentials or personal data on the site. Block the domain and IP at network perimeter and DNS levels using threat feeds. Report the domain to PhishDestroy, browser vendors, and domain registrars for takedown. If credentials were entered, rotate passwords immediately, enable multi-factor authentication where possible, and monitor accounts for unauthorized access. Organizations should update browser policies and security controls to block newly registered domains with low reputation scores and no historic content. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260423-AFC187 Favicon MD5: 3f06a11750ee367d1b5e4ca2fc4c0e30 TLS cert SHA-256: 06e2546e1f6051af7b8f624424efada3afbcdd9bfafcc1870378f0f63a6f2451 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/starlightgc.icu/ JSON API: https://api.destroy.tools/v1/check?domain=starlightgc.icu Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io