MALICIOUS — CRITICAL
foxwayshipping[.]com
This domain, foxwayshipping.com, is confirmed to operate as a credential harvesting platform targeting individuals in the logistics and shipping sectors.
- VirusTotal
- 9/91
- Blocklists
- No stored match
- Disponibilité
- Dernier actif connu · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@estoxy.com.
The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
foxwayshipping.com — Dernier actif connu (HTTP 200). Type d'arnaque : Credential Phishing. Résumé des preuves: VirusTotal 9/91 (ADMINUSLabs, alphaMountain.ai, CRDF, CyRadar, Emsisoft); PhishDestroy score 97/100. Bureau d’enregistrement: NameCheap.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Evidence Analysis
foxwayshipping.com: Credential Harvesting Site for Logistics
foxwayshipping.com is a confirmed credential harvesting site impersonating a shipping company, using a Let's Encrypt SSL certificate to appear legitimate.
This domain, foxwayshipping.com, is confirmed to operate as a credential harvesting platform targeting individuals in the logistics and shipping sectors. Analysis of the site's infrastructure reveals it mimics legitimate shipping company portals, presenting a fraudulent login interface designed to capture corporate credentials, payment details, and personal identification information. The domain's page title, 'Fox Way Shipping Company,' reinforces the deception by adopting a plausible corporate identity, while the use of common web technologies such as Bootstrap, jQuery, and FancyBox further obscures its malicious intent by replicating the user experience of authentic business websites. Infrastructure analysis provides concrete indicators of compromise. The domain resolves to the IP address 37.49.229.75 and was registered through NameCheap, Inc. on February 11, 2026, an unusually future-dated creation that may indicate domain spoofing or registry manipulation. Security vendor detections on VirusTotal report 16 out of 95 engines flagging the domain as malicious, while it appears on one security blocklist and is referenced in one AlienVault OTX threat intelligence pulse. The domain holds a Scamadviser trust score of 1/100 and a Gridinsoft trust score of 1/100, both indicating negligible legitimacy. Additionally, the domain is actively blocked by PhishDestroy, a specialized anti-phishing system. Users who have visited foxwayshipping.com or interacted with its content should immediately revoke any entered credentials, particularly those associated with corporate accounts or financial systems. Network administrators are advised to block the IP address 37.49.229.75 at the perimeter and monitor for outbound connections to this endpoint. Affected individuals should conduct a full system scan using updated security tools to detect potential secondary infections or data exfiltration artifacts. Organizations in the logistics sector should alert employees to this campaign and reinforce training on recognizing credential harvesting attempts, particularly those leveraging SSL certificates and professional-grade web design.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Couverture des données14 recorded checks
Signaux de sécurité
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 8 identified
Bootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
getbootstrap.com Confiance à 100 %Select2 is a jQuery based replacement for select boxes. It supports searching, remote data sets, and infinite scrolling of results.
select2.org Confiance à 100 %jQuery UI is a collection of GUI widgets, animated visual effects, and themes implemented with jQuery, Cascading Style Sheets, and HTML.
jqueryui.com Confiance à 100 %jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com Confiance à 100 %FancyBox is a tool for displaying images, html content and multi-media in a Mac-style 'lightbox' that floats overtop of web page.
fancyapps.com Confiance à 100 %Popper is a positioning engine, its purpose is to calculate the position of an element to make it possible to position it near a given reference element.
popper.js.org Confiance à 100 %HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confiance à 100 %Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of foxwayshipping.com · checked Jun 26, 2026
Données factuelles et rapports externesIndependent lookups and source reports
PD-20260429-F91D93 Recipient: abuse@estoxy.com Victim safety and official reportingImmediate actions and verified reporting channels
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.