# paystoret.pro — SUSPICIOUS > paystoret.pro poses as a payment service but is a confirmed phishing scam flagged by 2 of 95 VirusTotal vendors. ## Summary PhishDestroy identifies paystoret.pro as an active PayPal phishing domain posing as a legitimate payment service, currently marked with an elevated risk level. This domain was flagged by 2 of 95 VirusTotal vendors, registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, and resolves to IP 172.67.149.254. paystoret.pro was created on March 11, 2026, and currently lacks significant trust indicators. Current status demonstrates active deployment with minimal detection coverage, increasing the risk of successful credential theft or financial fraud. Users are advised to avoid interacting with paystoret.pro entirely and report any encountered phishing attempts. Organizations should block this domain at the network level and update threat intelligence feeds to prevent accidental exposure. If financial or login credentials were entered, immediately reset passwords, enable two-factor authentication, and monitor accounts for unauthorized activity. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-11 09:47:30 - Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED - IP: 172.67.149.254 ## Detection Status - VirusTotal: 2 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/c8cd0123-cc46-4cd6-89a9-8f5e9f345f81 - PhishDestroy: https://phishdestroy.io/domain/paystoret.pro/ - LLM endpoint: https://phishdestroy.io/domain/paystoret.pro/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/paystoret.pro/ Last updated: 2026-03-23