deliveryexpress[.]sa[.]com
“deliveryexpress.sa.com - Transport & Logistics Service”
संग्रहीत पहचान
क्लोकिंग चेतावनी
- क्लोकिंग प्रकार
status_split- क्लोकिंग स्कोर
- 2/6
साक्ष्य सारांश
On July 22, 2026 analysts observed that the domain deliveryexpress.sa.com is currently offline but was previously identified as a brand impersonation conduit targeting Google. The site was taken down and blocked by the PhishDestroy sinkhole, indicating that active mitigation has been applied. Technical examination shows the domain resolves to IP address 185.255.122.94, which is hosted in Ukraine and belongs to AS30860 operated by Virtual Systems LLC. No SSL certificate was presented, meaning all traffic would have been unencrypted, a common characteristic of low‑cost impersonation campaigns. Nameserver records list ns1.centralnic.net, ns2.centralnic.net, ns3.centralnic.net, and ns4.centralnic.net, all pointing to the CentralNic registry infrastructure.
The registrar for the domain is Sav.com, LLC, suggesting the registration was performed through a commercial registrar rather than a privacy‑protected service. The page title returned by the HTTP response is "deliveryexpress.sa.com - Transport & Logistics Service," which does not reference Google and provides no immediate indication of the intended brand abuse. Gridinsoft assigned a trust score of 0 out of 100, reflecting a highly malicious reputation. The domain appears on a single security blocklist, and VirusTotal reports indicate the domain was scanned by 95 vendors without any detections, a result that should not be interpreted as confirmation of safety.
The primary uncertainty lies in the exact content that was served before the takedown; no screenshots or login pages have been recovered, and the specific phishing kit or credential‑stealing mechanisms remain unknown. Defenders should continue to block the domain at perimeter filters, monitor the associated IP range for any resurgence, and add the domain to internal blacklists. Further investigation of the hosting provider and any related domains sharing the same nameserver set may reveal additional infrastructure used in the campaign.
Data Coverage
सुरक्षा संकेत
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 10/08/2026
पहचान समयरेखा
-
डोमेन स्थिति
पहुँच योग्य → पहुँच योग्य नहीं
-
Cloudflare Radar
Cloudflare Radar स्कैन संग्रहीत · स्कैन खोलें
-
डोमेन स्थिति
पहुँच योग्य नहीं → पहुँच योग्य
वायरसटोटल विश्लेषण
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।