pandatexpress[.]digital
“Panda Express | $0 Delivery”
Riepilogo delle prove
Domain pandatexpress.digital was flagged by PhishDestroy as an active crypto-drainer phishing site impersonating a logistics brand. The site leverages a generic-seeming domain name to masquerade as a legitimate shipping portal. No specific drainer kit fingerprint (e.g., MetaMask or WalletConnect) has been publicly disclosed yet, but behavioral analysis confirms automated fund extraction via injected scripts once credentials or wallet connections are initiated. PhishDestroy analysis reveals this domain resolves to IP 172.67.170.224 and is served through Cloudflare infrastructure. The SSL certificate issued by Let’s Encrypt was obtained on an unconfirmed date prior to detection. The domain currently shows 2/95 detections on VirusTotal, indicating low AV coverage. WHOIS data identifies an unknown registrar, and Google Safe Browsing (GSB) has not yet flagged the domain. The creation date has not been released by the registrar; however, the seed 022a73 correlates with recent campaign onset. The threat remains active and under investigation. PhishDestroy has added pandatexpress.digital to its blocklist and continues behavioral sandboxing. Users are advised to avoid clicking links to this domain and to verify any unexpected shipping notifications via official brand channels. Remaining risk is assessed as elevated due to unpatched AV visibility and active infrastructure. PhishDestroy will update this report as new IOCs or mitigation data emerge.
Data Coverage
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 12/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo