express48h-delivery[.]shop
“ZE Express | Bebidas geladas”
express48h-delivery.shop — Contenuto non disponibile. Simulazione del marchio: Apple; Tipo di truffa: Impersonation. Riepilogo delle prove: VirusTotal 16/91 (alphaMountain.ai, BitDefender, Cluster25, CRDF, ESET); URLQuery 5 alerts; CF Radar malicious; PhishDestroy score 95/100.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
The domain express48h-delivery.shop is currently listed as active and associated with a high‑risk delivery‑scam operation. Intelligence sources confirm that the domain resolves to the IPv4 address 88.80.17.231 and is served by the authoritative name servers ns1.dyna-ns.net and ns2.dyna-ns.net. Reputation checks show that three of ninety‑one security vendors on VirusTotal have flagged the domain, indicating that a minority of scanners have detected malicious indicators, while the majority have not raised an alert.
The domain is present on one external security blocklist and has been explicitly blocked by the PhishDestroy mitigation service, reinforcing the view that it is being used for fraudulent activity. No additional contextual data such as page title, SSL certificate details, HTTP response codes, or brand targeting are available in the current intelligence set, leaving the exact phishing payload and victim‑interaction flow unconfirmed. Analysts should prioritize containment of traffic to 88.80.17.231 and enforce DNS‑level blocking for both ns1.dyna-ns.net and ns2.dyna-ns.net to disrupt the infrastructure.
Continuous monitoring of VirusTotal updates and blocklist expansions is recommended to capture any changes in detection rates. Organizations that handle delivery confirmations or logistics communications should treat any unsolicited messages referencing express48h-delivery.shop as suspicious, verify sender authenticity through independent channels, and avoid clicking links or providing personal data until the domain’s activity is fully mitigated.
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | express48h-delivery.shop |
malicious | Sinkholed |
| OpenDNS | express48h-delivery.shop |
phishing | Phishing Block |
| DNS4EU | express48h-delivery.shop |
malicious | Sinkholed |
| CIRA Canadian Shield DNS | express48h-delivery.shop |
malicious | Sinkholed |
| Cloudflare DNS | express48h-delivery.shop |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Riscontro delle informazioni sulle minacce · source references
Tecnologie · 4 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org Confidenza al 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confidenza al 100%BigDataCloud IP Geolocation API provides detailed and accurate locality and security metrics of an IP address.
www.bigdatacloud.com Confidenza al 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confidenza al 100%Analisi di VirusTotal
Prove archiviate
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of express48h-delivery.shop · checked Aug 6, 2026
Dati e relazioni esterne
PD-20260806-42B11B Recipient: abuse@dcs.net Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo