ctp21039[.]top
“Cryptomus Pay”
ctp21039.top — Contenu indisponible. Usurpation de l'identité de la marque : PayPal; Type d'arnaque : Brand Impersonation. Résumé des preuves: VirusTotal 0/94; PhishDestroy score 48/100. Bureau d’enregistrement: Gname.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
PhishDestroy’s ongoing investigation has flagged ctp21039.top as a live PayPal brand impersonation phishing site targeting unsuspecting users. The domain employs spoofed login pages designed to harvest PayPal credentials, payment information, and personal data under the guise of a routine security or account update. Once harvested, attackers can execute unauthorized transactions, lock legitimate accounts, and commit identity fraud. The page relies on psychological pressure—urgent language and fake alerts—to override caution, making it especially dangerous for mobile users on slow connections where visual cues are harder to spot.
This domain was flagged within hours of its April 05, 2025 creation. Registry data shows registration through Gname.com Pte. Ltd., and the site resolves to IP 172.67.202.188 behind an active Google Trust Services SSL certificate. VirusTotal currently shows 0 detections out of 95 scanning engines, indicating it remains unflagged by most antivirus platforms as of today. The combination of a freshly minted domain, low reputation IP space, and valid TLS certificate is a common tactic to evade detection while building trust with victims.
If you visited ctp21039.top or entered any credentials, assume your PayPal account has been compromised. Immediately log in through PayPal’s official app or website—never via email links or search results—and enable two-factor authentication. Revoke any unfamiliar devices linked to your account, change passwords everywhere reused, and monitor bank statements for unauthorized charges. Report the incident to PayPal’s fraud line and file a complaint with your national cybercrime unit. If you did not submit information but remain concerned, run a full antivirus scan and check browser extensions for unauthorized access. Share this alert to help others avoid the same trap.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 8 identified
Popular CSS framework for responsive, mobile-first web development.
Conversion and audience tracking pixel for paid campaigns on X (Twitter) — signals that the site runs paid X ads.
business.x.comFast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comWeb analytics service tracking website traffic and user behavior.
marketingplatform.google.comConversion-tracking pixel by Meta — logs page views and custom events to Facebook/Instagram ad accounts.
www.facebook.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of ctp21039.top · checked Mar 28, 2026
Données factuelles et rapports externes
PD-20260328-AA0D17 Recipient: complaint@gname.com Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif