# PhishDestroy threat dossier — stonebridgeaxis.com ================================================================ Fetched: 2026-07-28 22:28:31 UTC Canonical: https://phishdestroy.io/domain/stonebridgeaxis.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 97/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain Flagging vendors: Bfore.Ai PreCrime AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 92.113.16.63 (LT, Vilnius) ASN: AS47583 Hostinger International Limited Hosting org: Hostinger International Ltd. Registrar: HOSTINGER operations, UAB Nameservers: ns1.dns-parking.com, ns2.dns-parking.com Registered: 2026-03-13 Expires: 2027-03-13 Page title: Stonebridge Axis - Home HTTP response: 403 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE2 Expires: 2026-10-09 Status: INVALID chain Fingerprint: b146516fd7f6e1fe2a2f6de61fffe1ada005b740cfcc8c5a1026179a52d551fd Subject Alternative Names (related infrastructure — often same operator): - www.stonebridgeaxis.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-03-13 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 08:12:33 UTC (by PhishDestroy tracker) First reported: 2026-07-27 09:28:58 UTC (abuse notice filed) Last verified: 2026-07-29 00:20:28 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa247-cb6c-74a6-ac65-795c3e3087d4/ URLQuery: https://urlquery.net/report/4aeb1612-dd9e-4193-8922-c73e3deff465 Wayback Machine: https://web.archive.org/web/*/stonebridgeaxis.com crt.sh CT logs: https://crt.sh/?q=%25.stonebridgeaxis.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=stonebridgeaxis.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/stonebridgeaxis.com URLhaus: https://urlhaus.abuse.ch/host/stonebridgeaxis.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 08:14:54 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is stonebridgeaxis.com a Phishing Site? Analysis of stonebridgeaxis.com shows a newly created domain that is actively resolving to the IPv4 address 88.222.222.161. Registration records indicate the domain was created on March 13, 2026 and was registered through HOSTINGER operations, UAB, a registrar commonly associated with shared web‑hosting services. The domain is served by the generic parking nameservers ns1.dns-parking.com and ns2.dns-parking.com, suggesting that the attacker is leveraging inexpensive registration and hosting infrastructure. VirusTotal has logged one detection out of ninety‑one scanning engines, confirming that at least one security product has identified the domain as malicious. Independent verification by the PhishDestroy blocklist confirms that the domain is already being used for malicious activity and has been actively blocked. Additionally, the domain appears on a single known security blocklist, reinforcing the view that it is part of an operational phishing campaign. No public page title, SSL certificate details, or Safe Browsing verdict are currently available, leaving the exact content and target brand of the phishing attempt undocumented. Defenders should treat stonebridgeaxis.com as a high‑risk indicator: block DNS resolution and HTTP/S traffic to the domain, add the IPv4 address 88.222.222.161 to network‑level deny lists, and monitor outbound connections for any attempts to reach the host. Continuous feed updates from VirusTotal, PhishDestroy, and any additional blocklists are recommended to capture new detections, and security teams should consider sandboxing any retrieved payloads associated with the domain for deeper behavioral analysis. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-5A5A30 Favicon MD5: 2ecb1d7fa8d7a27c13e5ce8e66fc5294 TLS cert SHA-256: b146516fd7f6e1fe2a2f6de61fffe1ada005b740cfcc8c5a1026179a52d551fd ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/stonebridgeaxis.com/ JSON API: https://api.destroy.tools/v1/check?domain=stonebridgeaxis.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 208,135 domains (82,977 alive under monitoring, 124,126 confirmed takedowns/dead). Site: https://phishdestroy.io