The domain logistica-jadlog-encomenda-rastreada.com was registered on July 31, 2026 through GoDaddy.com, LLC and is currently pointed at the Cloudflare nameservers dion.ns.cloudflare.com and riya.ns.cloudflare.com. DNS resolution returns the address 104.21.14.249, a Cloudflare‑owned IP range that is frequently leveraged for malicious hosting. The domain appears on a single external blocklist and has been explicitly added to the PhishDestroy blocklist, indicating that at least one security vendor has observed malicious activity associated with it.
VirusTotal reports that the domain has been scanned by 91 antivirus and URL‑reputation engines; none of the engines have raised a detection, but the absence of a flag does not constitute evidence of benign intent. No public information is available regarding SSL certificate details, HTTP response codes, page title, or any observed payloads, so the exact phishing vector remains unconfirmed. The current evidence points to a newly created domain used in a credential‑harvesting campaign, likely targeting users of logistics or courier services based on the lexical components of the name.
Defenders should proactively block the domain and its resolving IP at network perimeters, monitor DNS queries for the domain, and consider adding the IP to reputation‑based deny lists. Continuous re‑evaluation is advised, as additional telemetry such as page content, request patterns, or victim reports could clarify the scope and technique of the campaign.