paypal-login[.]de
“paypal-login.de”
اكتشاف محفوظ
تنبيه إخفاء المحتوى
- نوع الإخفاء
redirect_split- درجة الإخفاء
- 3/6
ملخص الأدلة
PhishDestroy has identified paypal-login.de as an elevated risk phishing site engaged in brand impersonation of PayPal. This domain is actively being used to deceive users into entering their sensitive login credentials on a fraudulent interface that mimics PayPal's official sign-in page. The threat is classified as a fake login attack, specifically targeting PayPal customers, and is currently active and operational. Users who encounter this site risk having their account credentials stolen and potentially their financial information compromised.
Technical analysis of paypal-login.de reveals several red flags that confirm its malicious nature. The domain was registered on April 28, 2026, which is very recent, a common tactic used by cybercriminals to avoid detection. It is hosted on IP address 144.76.59.138, and its SSL certificate is issued by Let's Encrypt (R12), which provides a false sense of security. On VirusTotal, 16 out of 95 security vendors flag this domain as malicious, and it appears on one security blocklist. The site's page title is simply 'paypal-login.de,' lacking any legitimate branding, and it resolves to a server likely controlled by threat actors.
To protect against this specific phishing threat, users should never enter their PayPal credentials on any site other than the official PayPal domain (paypal.com). Always verify the URL in the address bar before logging in, and enable two-factor authentication on your PayPal account for an added layer of security. If you have already submitted information on this fraudulent site, change your PayPal password immediately and contact PayPal support to report the incident. PhishDestroy recommends using a reputable password manager to automatically detect and avoid phishing sites, and to regularly monitor your account for unauthorized transactions.
Data Coverage
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | s.cdn-fileserver.com |
malicious | Sinkholed |
| Quad9 DNS | s.cdn-fileserver.com |
malicious | Sinkholed |
| DigiCert UltraDNS | l.cdn-fileserver.com |
malicious | Sinkholed |
| Quad9 DNS | l.cdn-fileserver.com |
malicious | Sinkholed |
| Hagezi Threat Feed | findresultshub.com |
malicious | Sinkholed |
| Quad9 DNS | findresultshub.com |
malicious | Sinkholed |
| Quad9 DNS | paypal-login.de |
malicious | Sinkholed |
| DNS4EU | paypal-login.de |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of paypal-login.de · checked Apr 28, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب