Skip to security report
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 8. Exercise extreme caution — do not enter credentials or personal information.
Domain security and threat intelligence

158-158-1-61[.]cprapid[.]com

“DPD (fr) |”

Threat verdict Critical 78/100 evidence score
Availability Unverified Current reachability is unverified
VirusTotal detections: 8/91 Brand impersonation: Dpd
Jul 30, 2026 Dpd
Evidence Summary
CRITICAL
Ref
4C39797A
Score
78/100

Analysis of 158-158-1-61.cprapid.com shows a high‑risk, active generic phishing infrastructure. The domain is hosted on cPanel Rapid, a shared hosting platform that frequently supplies disposable domains for malicious campaigns. DNS resolution points to the IPv4 address 158.158.1.61, confirming a single‑point hosting footprint. The domain appears on one public security blocklist and has been flagged by the PhishDestroy sinkhole, indicating that it has already been identified as malicious by at least one anti‑phishing service.

VirusTotal reports that 2 of 91 scanned security vendors classify the domain as malicious, providing independent confirmation of its threat status. No additional intelligence such as Safe Browsing, Open Threat Exchange, SSL certificate details, or HTTP response codes is currently available, leaving the full surface‑area of the site’s content and transport security unverified. Given the confirmed registrar (cPanel Rapid), the presence on a blocklist, and the VirusTotal detections, defenders should treat any traffic to this domain as hostile.

Recommended mitigations include adding the domain to local deny lists, updating proxy and firewall rules to block outbound connections to 158.158.1.61, and ensuring that email filters reference the blocklist entry. Continuous monitoring of the domain’s resolution and any future VirusTotal scans is advised to capture changes in detection coverage. Organizations should also verify that endpoint protection solutions are configured to flag the domain based on the existing detections, and consider sharing indicator data with threat‑sharing communities to improve collective defenses.

VirusTotal
VirusTotal
8 det.
URLScan
URLScan
ScamAdviser
Scamadviser
80/100
TLS Certificate
Expired or unverified
Observed status
Unverified
PhishDestroy
DestroyList
Listed
Data coverage VirusTotal 8 / 91 URLQuery not checked PhishStats not checked OTX no community references CF Radar scan completed URLScan capture stored report URLScan verdict malicious DNS blocks not checked TLS Expired or unverified WHOIS not parsed Screenshot 3 captures · 2 sources Redirect chain not probed Scamadviser 80/100
Network Security Intelligence
SSL Certificate Invalid
SSL certificate is invalid or expired. Issuer: Let's Encrypt

Threat Response Pipeline

Discovery
Checks
Reports
Availability
11/13

Public Blocklist Status

Stored Capture

Page Title
DPD (fr) |
TLS Certificate
Expired or unverified · Issued by Let's Encrypt · valid for 88 days

Domain Intelligence

Domain
URLScan Verdict Malicious score 100 Phishing brand: Dpd report ↗
Server / ASN Apache · AS8075 Microsoft Corporation
IP Reputation abuse score 0/100 0 reports checked Jul 30, 2026
Registrar (base domain) cPanel Rapid
IP Address 158.158.1.61 ES
GeoES Madrid, ES
NetworkAS8075 · Microsoft Azure Cloud (spaincentral)
Technical detailsDNS, SSL SANs, timestamps
First DetectedJul 30, 2026
DOM Analysisanalyzed Jul 30, 2026score 78/100
IoC Extractionscanned Aug 1, 20260 wallet · 0 Telegram IoCs
Submitted URLhttp://158-158-1-61.cprapid.com/pl/update.php
TLS Fingerprint
TLS Observationvalid from Jul 29, 2026scanned Jul 30, 2026
TLS SAN Domainsipv6.paket.info.158-158-1-61.cpanel.sitemail.paket.info.158-158-1-61.cpanel.sitepaket.info.158-158-1-61.cpanel.sitewww.paket.info.158-158-1-61.cpanel.site
ICANN OVERSIGHT Registration: cprapid.com

Accreditation and RAA context

Registrar accreditation and DNS abuse obligations

For the registrable domain cprapid.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Nothing is sent automatically.
Threat Intel Cross-Reference · source references
ScamAdviser Public lookup
A public ScamAdviser lookup is available. Review its current score and warnings at the source; the existence of a lookup page is not itself a malicious verdict.
View on ScamAdviser
Live-fetched via CF worker proxy pool · cached 24h
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

8 / 91 security vendors flagged this domain
View on VT
Last analyzed Previous stored snapshot: 7 detections
alphaMountain.ai
Forcepoint ThreatSeeker
Gridinsoft
Lionic
MalwareURL
Seclookup
Sophos
Webroot

Archived Evidence

Wayback Machine Snapshot
A historical snapshot is available for evidence review
View Archive
Stored Capture Evidence 1 snapshot

Timestamped response metadata retained by the local collection pipeline. Each value below belongs to the displayed archive time.

Archived HTTP response HTTP 200
Requested URL: http://158-158-1-61.cprapid.com/pl/update.php
DPD (de) |
Response
HTTP 200
HTML body
37.4 KB
Compressed
6.9 KB
Links
6 internal · 16 external
Detected technologies
wordpressapache
Selected response headers
Server: Apache
Cache-Control: no-store, no-cache, must-revalidate
Content-Type: text/html; charset=UTF-8
HSTS: not observed DNSSEC: not observed WAF / firewall: observed Cloaking flag: not observed
Favicon fingerprint: a3121842a3e247b2c064c1b5b308f5df597226e3258bb46c9feffbc962d9d040
All stored response-header names (9)
DateServerExpiresCache-ControlPragmaKeep-AliveConnectionTransfer-EncodingContent-Type

Evidence & External Reports

Were You Affected by This Site?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself

Check Any Domain

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

Scan Now

Report Phishing

Submit suspicious domains to our threat database — protect the community

Report

Live Threat Feed

Recent phishing reports and observed availability changes

Monitor

Stay Informed, Stay Safe

Monitor live threats or contest this listing if you believe it's a false positive

Live Threat Feed Appeal This Listing
HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/158-158-1-61.cprapid.com"
  title="PhishDestroy threat report for 158-158-1-61.cprapid.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

A Very Sincere Thank-You Note

Satirical draft generator

Recipient
Fee context

Satirical draft. Fee figures are estimates; exact attribution to this domain is not claimed.