Skip to security report
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 20. Exercise extreme caution — do not enter credentials or personal information.
Domain security and threat intelligence

post-swiss[.]pro

Phishing and security check for post-swiss.pro

“Accès refusé”

Threat verdict Critical 95/100 evidence score
Availability Content unavailable Content was unavailable in the latest observation
Risk signals
VirusTotal detections: 20/94 Spamhaus DBL: DBL_PHISH URLQuery threat systems: 6 alerts Brand impersonation: Sui
20/94 VT URLQuery: 6 threat alerts Apr 21, 2026 Unavailable since Apr 22, 2026 Sui Credential Phishing 1 Report Sent 11h to unavailable NL NL
Evidence Summary
CRITICAL
Ref
E8AB17E1
Score
95/100

PhishDestroy identifies post-swiss.pro as an active fake-login phishing domain currently impersonating Swiss Post Finance and leveraging a crypto drainer payload to harvest banking credentials and digital assets.

This domain was flagged by 16 of 95 VirusTotal security vendors and is currently blocked by the OISD blocklist. Technical indicators include resolution to IPv4 address 45.153.34.184, a Let’s Encrypt SSL certificate, and presence on one additional public blocklist; VirusTotal detection ratio sits at 16/95. Registrar and creation date data remain unverified due to throttled WHOIS queries, limiting historical visibility.

Given the elevated risk level, users are strongly advised against interacting with post-swiss.pro. The domain remains active and capable of exfiltrating sensitive financial data. Run an immediate safety check on PhishDestroy using seed e8ab17 or submit the URL for real-time scanning to prevent credential theft and unauthorized fund transfers.

VirusTotal
VirusTotal
20 det.
URLQuery
URLQuery
6 threat alerts
DNS Security
6/12
CF Radar
Malicious
URLScan
URLScan
TLS Certificate
Let's Encrypt
Age
4 mo
Observed status
Content unavailable 502
PhishDestroy
DestroyList
Listed
Reports Sent
1
Data coverage VirusTotal 20 / 94 URLQuery 6 threat-system alerts PhishStats checked — no match recorded OTX no community references CF Radar provider verdict: malicious URLScan capture stored report URLScan verdict Analysis completed DNS blocks 6/12 TLS valid certificate, 85d WHOIS 4 mo old Screenshot 3 captures · 3 sources Redirect chain not probed
Network Security Intelligence
DNS Provider Blocks 6 / 12
Adguard Default Adguard Family Controld Adblock Controld Family Controld Malware Quad9 Secure
Threat Detection Systems 6 alerts
Detection System Indicator Verdict Alert
Cloudflare DNS post-swiss.pro malicious Sinkholed
OpenDNS post-swiss.pro phishing Phishing Block
DigiCert UltraDNS post-swiss.pro malicious Sinkholed
Hagezi Threat Feed post-swiss.pro malicious Sinkholed
Quad9 DNS post-swiss.pro malicious Sinkholed
DNS4EU post-swiss.pro malicious Sinkholed
CF Cloudflare Radar Verdict Malicious
Phishing Security threats Phishing Security Risks

Threat Response Pipeline

Discovery
Checks
Reports
Availability
15/15
Sent Report Recorded
Stored sent-report record for domain registrar, hosting provider, 1 abuse contact
abuse@vmheaven.io
Apr 21, 2026

Public Blocklist Status

Stored Capture

Domain Intelligence

Domain
URLScan Verdict Analysis completed score 0 report ↗
Server / ASN nginx · AS51396 Pfcloud UG
IP Reputation abuse score 0/100 0 reports checked Jul 14, 2026
Registrar Unknown
Abuse contactabuse@vmheaven.io
IP Address 45.153.34.184 NL
GeoNL Eygelshoven, NL
NetworkAS51396 · VMHeaven.io
RegistrationCreated Apr 21, 2026 (109d)
HTTP Status502 Error
Time to First Unavailability 11h
What we count Elapsed time from the first stored abuse report to the first observation that the content was unavailable. This does not establish the cause.
What each report contains Stored outgoing-report records may reference evidence available at the time, such as vendor verdicts, registration data, hosting details, classifications, or screenshots. This page does not infer the exact payload delivered, receipt, acknowledgement, or action by a recipient.
Technical detailsDNS, SSL SANs, timestamps
First DetectedApr 21, 2026
DOM Analysisanalyzed Jul 29, 2026score 73/100
IoC Extractionscanned Aug 1, 20260 wallet · 0 Telegram IoCs
Submitted URLhttp://post-swiss.pro/
Nameserverscuritiba.ns.porkbun.comfortaleza.ns.porkbun.commaceio.ns.porkbun.comsalvador.ns.porkbun.com
TLS Fingerprint
TLS Observationvalid from Apr 16, 2026scanned Apr 21, 2026
TLS SAN Domainswww.post-swiss.pro
Case ID
Page Title
Accès refusé
TLS Certificate
Valid transport encryption · Issued by Let's Encrypt · valid for 85 days
Technologies · 4 identified
Plesk
Hosting panels

Plesk is a web hosting and server data centre automation software with a control panel developed for Linux and Windows-based retail hosting service providers.

www.plesk.com 100% confidence
PHP
Programming languages

PHP is a general-purpose scripting language used for web development.

php.net 100% confidence
Nginx
Web servers Reverse proxies

Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.

nginx.org 100% confidence
HSTS
Security

HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.

www.rfc-editor.org 100% confidence
Detected via Cloudflare Radar · Wappalyzer engine
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

20 / 94 security vendors flagged this domain
View on VT
Last analyzed
ADMINUSLabs
alphaMountain.ai
Chong Lua Dao
Cluster25
CRDF
CyRadar
ESET
Emsisoft
Fortinet
G-Data
Kaspersky
LevelBlue
Lionic
MalwareURL
Netcraft
Seclookup
SOCRadar
Sophos
VIPRE
Webroot
Site Performance Analysis

Google PageSpeed Insights — mobile performance audit of post-swiss.pro · checked Apr 21, 2026

99
Good
Performance
FCP
1.78s
First Contentful Paint
LCP
1.78s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
1.83s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

Evidence & External Reports

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260421-4B2B02 Recipient: abuse@vmheaven.io
Page title stored with report: Accès refusé
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 16.2 KB

Were You Affected by This Site?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself

Check Any Domain

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

Scan Now

Report Phishing

Submit suspicious domains to our threat database — protect the community

Report

Live Threat Feed

Recent phishing reports and observed availability changes

Monitor

Stay Informed, Stay Safe

Monitor live threats or contest this listing if you believe it's a false positive

Live Threat Feed Appeal This Listing
HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/post-swiss.pro"
  title="PhishDestroy threat report for post-swiss.pro"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>