Analysis of the domain zedeliverys-express.shop indicates active infrastructure supporting a delivery‑related scam. The domain resolves to the IPv4 address 88.80.17.231 and is served by the authoritative name servers ns1.dyna-ns.net and ns2.dyna-ns.net. Both PhishDestroy and OpenPhish have listed the domain on their phishing blocklists, confirming that it is currently recognized by at least two independent threat‑intelligence feeds.
VirusTotal reports that seven of ninety‑one scanned security vendors flag the domain, reinforcing the notion that malicious activity is associated with the host. The domain appears on two security blocklists, and its status is marked as active, suggesting ongoing operation. No registrar information, SSL/TLS certificate details, HTTP response codes, or page‑title metadata are available in the supplied intelligence, leaving those surface‑level indicators unverified.
Given the confirmed resolution to a single IP address, the hosting environment appears centralized, which may simplify takedown or sink‑hole actions for defenders. Operators should continue to block the domain at DNS and proxy layers, monitor outbound connections to 88.80.17.231, and incorporate the domain into existing URL filtering policies. Continued observation of the associated IP and name server infrastructure is advised to detect potential migration or re‑use in future campaigns.