ferryman[.]co[.]za
“Ferryman Collections - Ferryman Collections”
Evidence Summary
This domain, ferryman.co.za, was registered on 21 February 2026 and is currently active. It resolves to the Cloudflare‑owned address 104.21.46.13 (ASN 13335) and uses Cloudflare’s authoritative nameservers noel.ns.cloudflare.com and mira.ns.cloudflare.com. The site serves a page titled “Ferryman Collections – Ferryman Collections” and presents a WordPress installation with MySQL, PHP, Slider Revolution, jQuery, and HTTP/3 enabled. The TLS certificate is issued by Google Trust Services under the WE1 chain, providing a valid HTTPS connection. Email routing is handled by mx.stackmail.com (priority 10), a service distinct from the hosting provider, which may be leveraged for credential‑collection activities. The presence of a fully functional WordPress stack indicates the site can host malicious forms or payloads. Reputation data shows the domain is flagged by one of ninety‑five VirusTotal scanners, receives a zero score from Gridinsoft, and appears on a single external blocklist. PhishDestroy has already blocked the domain, confirming its use in a phishing campaign. No public indicators beyond these listings have been released, leaving the exact impersonated brand or lure content uncertain. Defenders should add ferryman.co.za to URL filtering and DNS sinkhole lists, block outbound connections to its IP address, and monitor for traffic to the associated MX host. Email gateways should enforce strict sender verification for messages claiming to originate from ferryman.co.za, and internal scanning for WordPress‑related implants is recommended, as the platform can be abused to host malicious payloads.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 11, 2026
10 monitored external feeds No match
Detection timeline
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of ferryman.co.za · checked Mar 2, 2026
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive