This domain, zeexpress-oficial.shop, is actively flagged as a high-risk phishing infrastructure targeting courier or logistics services. As of August 01, 2026, the domain remains operational and resolves to the IP address 88.80.17.231. Infrastructure analysis reveals the use of nameservers ns1.dyna-ns.net and ns2.dyna-ns.net, which are frequently associated with malicious or low-reputation hosting environments. The domain appears on two security blocklists, including PhishDestroy and OpenPhish, indicating prior detection and classification as a phishing threat.
Detection data from VirusTotal shows that 7 out of 91 security vendors have flagged the domain, suggesting moderate but not universal recognition of its malicious nature. The absence of additional context—such as SSL certificate details, HTTP response codes, or page content—limits further technical assessment. However, the domain's presence on multiple blocklists and its association with a hosting provider linked to phishing campaigns provide sufficient evidence to treat it as a confirmed threat. Defenders should prioritize blocking this domain at the DNS or network level, particularly in environments where users may interact with courier or delivery service communications.
Monitoring for related domains using the same nameservers or IP range (88.80.17.231) may help identify additional malicious infrastructure. Given the domain's active status and lack of legitimate indicators, no further validation is required before implementing protective measures. If additional telemetry becomes available—such as phishing kit signatures or targeted brand confirmation—it should be incorporated into detection rules to enhance coverage against similar threats.