go-pedido24h-ze[.]shop
“ZE Express | Bebidas geladas”
go-pedido24h-ze.shop — Inhalt nicht verfügbar. Betrugstyp: Credential Phishing. Zusammenfassung der Beweislage: VirusTotal 7/91 (CRDF, ESET, Forcepoint ThreatSeeker, Gridinsoft, Kaspersky); URLQuery 4 alerts; CF Radar malicious; PhishDestroy score 83/100. Registrar: Dynadot.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
This domain is flagged as a high-risk credential theft operation designed to harvest user login credentials and payment information under the guise of ZE Express, a legitimate beverage delivery service. Analysis indicates the site employs brand impersonation tactics, presenting itself as the official ZE Express portal with the page title 'ZE Express | Bebidas geladas' to deceive visitors into submitting sensitive data. Infrastructure analysis reveals multiple technical indicators of malicious activity. The domain go-pedido24h-ze.shop resolves to the IP address 88.80.17.179, hosted on AS33837 (Fredrik Holmqvist) in Sweden, a network segment previously associated with phishing campaigns. It was registered on June 17, 2024, through Dynadot Inc., a registrar frequently utilized for short-lived malicious domains. The domain appears on at least one security blocklist and is flagged by 7 out of 95 security vendors on VirusTotal, including detections for credential theft. The SSL certificate is issued by Let's Encrypt (YR1), a common choice for threat actors due to its free and automated issuance process. The domain's creation date aligns with typical phishing lifecycle patterns, suggesting it may be part of a larger, ephemeral campaign. Users and organizations are advised to implement mitigation measures specific to credential theft threats. Immediate actions include blocking the domain and its resolving IP (88.80.17.179) at the network perimeter, as well as deploying browser-based warnings for employees or customers attempting to access the site. Given the impersonation of ZE Express, affected users should be instructed to verify the legitimacy of any communication or website claiming affiliation with the brand by cross-referencing official domains and contacting the company through verified channels. Multi-factor authentication (MFA) should be enforced for all accounts to mitigate the impact of stolen credentials. Additionally, security teams are encouraged to monitor for indicators of compromise, such as unusual login attempts or unauthorized transactions, particularly for users who may have interacted with the domain.
Erkenntnisse zur Netzwerksicherheit
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | go-pedido24h-ze.shop |
malicious | Sinkholed |
| CIRA Canadian Shield DNS | go-pedido24h-ze.shop |
malicious | Sinkholed |
| Cloudflare DNS | go-pedido24h-ze.shop |
malicious | Sinkholed |
| OpenDNS | go-pedido24h-ze.shop |
phishing | Phishing Block |
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
ICANN OVERSIGHT
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologien · 4 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100 % KonfidenzHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100 % KonfidenzBigDataCloud IP Geolocation API provides detailed and accurate locality and security metrics of an IP address.
www.bigdatacloud.com 100 % KonfidenzHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % KonfidenzVirusTotal-Analyse
Nachweise und externe Berichte
PD-20260619-1756FB Recipient: abuse@prq.se Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt