xn--paypalgebhrenrechner-xec[.]de
Domain Security & Threat Intelligence Report
Analyst Security Overview
AI-GeneratedThe domain xn--paypalgebhrenrechner-xec.de impersonates PayPal, potentially deceiving users into providing sensitive information. It currently has a VirusTotal score of 19/95, indicating a significant risk of phishing activity. This domain is operational and aims to lure individuals with fake services related to PayPal.
This domain appears to be suspicious due to its recent registration and the lack of a verified registrar, which raises concerns about its legitimacy. It is hosted on an IP address (198.18.35.235) associated with malicious activities and is already blocklisted by two security services. The combination of these factors makes it a notable phishing threat.
PhishDestroy is actively monitoring xn--paypalgebhrenrechner-xec.de and has reported its malicious activities to relevant authorities. As of now, the domain is still alive, and continued vigilance is necessary to mitigate the risk it poses to PayPal users.
Threat Response Pipeline
Public Blocklist Status
Website Screenshot
Domain Intelligence
dns2.namecheaphosting.com
admin@mx2-hosting.jellyfish.systems
postmaster@mx2-hosting.jellyfish.systems
postmaster@mx3-hosting.jellyfish.systems
admin@mx3-hosting.jellyfish.systems
admin@mx1-hosting.jellyfish.systems
postmaster@mx1-hosting.jellyfish.systems
abuse@mx2-hosting.jellyfish.systems
abuse@mx3-hosting.jellyfish.systems
cpanel@tech.namecheap.com
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If you have interacted with this domain, entered personal information, or connected a cryptocurrency wallet — take immediate action. Below are resources to help you report the incident and protect yourself.
Report to Your Local Authorities
Select your country to see local cybercrime reporting contacts and complaint templates.
Related Domain Reports
More Domains at REGISTRAR_NOT_FOUND
Stay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive
URLScan Report