ctp21039[.]top
“Cryptomus Pay”
ctp21039.top — Contenuto non disponibile. Simulazione del marchio: PayPal; Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VirusTotal 0/94; PhishDestroy score 48/100. Registrar: Gname.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
PhishDestroy’s ongoing investigation has flagged ctp21039.top as a live PayPal brand impersonation phishing site targeting unsuspecting users. The domain employs spoofed login pages designed to harvest PayPal credentials, payment information, and personal data under the guise of a routine security or account update. Once harvested, attackers can execute unauthorized transactions, lock legitimate accounts, and commit identity fraud. The page relies on psychological pressure—urgent language and fake alerts—to override caution, making it especially dangerous for mobile users on slow connections where visual cues are harder to spot.
This domain was flagged within hours of its April 05, 2025 creation. Registry data shows registration through Gname.com Pte. Ltd., and the site resolves to IP 172.67.202.188 behind an active Google Trust Services SSL certificate. VirusTotal currently shows 0 detections out of 95 scanning engines, indicating it remains unflagged by most antivirus platforms as of today. The combination of a freshly minted domain, low reputation IP space, and valid TLS certificate is a common tactic to evade detection while building trust with victims.
If you visited ctp21039.top or entered any credentials, assume your PayPal account has been compromised. Immediately log in through PayPal’s official app or website—never via email links or search results—and enable two-factor authentication. Revoke any unfamiliar devices linked to your account, change passwords everywhere reused, and monitor bank statements for unauthorized charges. Report the incident to PayPal’s fraud line and file a complaint with your national cybercrime unit. If you did not submit information but remain concerned, run a full antivirus scan and check browser extensions for unauthorized access. Share this alert to help others avoid the same trap.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologie · 8 identified
Popular CSS framework for responsive, mobile-first web development.
Conversion and audience tracking pixel for paid campaigns on X (Twitter) — signals that the site runs paid X ads.
business.x.comFast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comWeb analytics service tracking website traffic and user behavior.
marketingplatform.google.comConversion-tracking pixel by Meta — logs page views and custom events to Facebook/Instagram ad accounts.
www.facebook.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of ctp21039.top · checked Mar 28, 2026
Dati e relazioni esterne
PD-20260328-AA0D17 Recipient: complaint@gname.com Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo