# paynote.cloud — MALICIOUS > Concerned about paynote.cloud? Discover why this high-risk phishing domain should be avoided to protect your personal and financial info. ## Summary PhishDestroy identifies paynote.cloud as a high-risk phishing domain related to fake invoicing services aimed at freelancers. This active site tries to trick users into sharing sensitive data by masquerading as a professional tool. The phishing works by presenting a convincing page titled 'PayNote - Professional Invoicing for Freelancers' to lure victims into inputting credentials or payment info. It currently resolves to 216.24.57.1 and is flagged on multiple security blocklists, with several threat intelligence alerts. If you have visited paynote.cloud, avoid entering any information and run a full security scan on your devices. Change passwords immediately if you submitted credentials, and monitor your accounts for suspicious activity to stay protected. ## Threat Details - Verdict: MALICIOUS - Site status: alive (HTTP 530) - Page title: PayNote - Professional Invoicing for Freelancers | PayNote ## Domain Intelligence - Registered: 2026-02-21 07:01:08 - IP: 216.24.57.1 - IP Country: US - IP City: San Francisco - IP Org: AS397273 Render - SSL Issuer: WE1 ## Detection Status - VirusTotal: 14 vendors flagged Vendors: ["ADMINUSLabs", "alphaMountain.ai", "BitDefender", "CRDF", "CyRadar", "ESET", "Forcepoint ThreatSeeker", "Fortinet", "G-Data", "Gridinsoft", "Phishing Database", "Seclookup", "SOCRadar", "Webroot"] - Google Safe Browsing: clean - Blocklists: 6 hits Lists: ["PhishDestroy", "MetaMask", "Polkadot", "Enkrypt", "Codeesura", "PhishingDB"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019af5de-967a-700c-85b5-56a683463520.png - PhishDestroy: https://phishdestroy.io/domain/paynote.cloud/ - LLM endpoint: https://phishdestroy.io/domain/paynote.cloud/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/paynote.cloud/ Last updated: 2026-03-19