ctp21039[.]top
“Cryptomus Pay”
ctp21039.top — المحتوى غير متوفر. انتحال العلامة التجارية: PayPal; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 0/94; PhishDestroy score 48/100. مسجّل النطاق: Gname.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
PhishDestroy’s ongoing investigation has flagged ctp21039.top as a live PayPal brand impersonation phishing site targeting unsuspecting users. The domain employs spoofed login pages designed to harvest PayPal credentials, payment information, and personal data under the guise of a routine security or account update. Once harvested, attackers can execute unauthorized transactions, lock legitimate accounts, and commit identity fraud. The page relies on psychological pressure—urgent language and fake alerts—to override caution, making it especially dangerous for mobile users on slow connections where visual cues are harder to spot.
This domain was flagged within hours of its April 05, 2025 creation. Registry data shows registration through Gname.com Pte. Ltd., and the site resolves to IP 172.67.202.188 behind an active Google Trust Services SSL certificate. VirusTotal currently shows 0 detections out of 95 scanning engines, indicating it remains unflagged by most antivirus platforms as of today. The combination of a freshly minted domain, low reputation IP space, and valid TLS certificate is a common tactic to evade detection while building trust with victims.
If you visited ctp21039.top or entered any credentials, assume your PayPal account has been compromised. Immediately log in through PayPal’s official app or website—never via email links or search results—and enable two-factor authentication. Revoke any unfamiliar devices linked to your account, change passwords everywhere reused, and monitor bank statements for unauthorized charges. Report the incident to PayPal’s fraud line and file a complaint with your national cybercrime unit. If you did not submit information but remain concerned, run a full antivirus scan and check browser extensions for unauthorized access. Share this alert to help others avoid the same trap.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
التقنيات · 8 identified
Popular CSS framework for responsive, mobile-first web development.
Conversion and audience tracking pixel for paid campaigns on X (Twitter) — signals that the site runs paid X ads.
business.x.comFast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comWeb analytics service tracking website traffic and user behavior.
marketingplatform.google.comConversion-tracking pixel by Meta — logs page views and custom events to Facebook/Instagram ad accounts.
www.facebook.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of ctp21039.top · checked Mar 28, 2026
الأدلة والتقارير الخارجية
PD-20260328-AA0D17 Recipient: complaint@gname.com هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب