go-delivery-marmitex[.]shop
“ZE Express | Bebidas geladas”
go-delivery-marmitex.shop — 콘텐츠를 사용할 수 없음. 증거 요약: VirusTotal 8/91 (alphaMountain.ai, CRDF, ESET, Gridinsoft, Kaspersky); URLQuery 5 alerts; CF Radar malicious; PhishDestroy score 78/100. 등록기관: Dynadot.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
Analysis of go-delivery-marmitex.shop, observed on 23 July 2026, indicates that the domain is associated with a delivery‑scam campaign. The domain is registered through Dynadot Inc. and uses the authoritative nameservers ns1.dyna-ns.net and ns2.dyna-ns.net. DNS resolution points to the IPv4 address 88.80.17.179, which is attributed to a PRQ Dynvpn hosting environment in Sweden (SE). The hosting provider does not publish a dedicated ASN, but the location suggests the infrastructure is operated from a VPN service commonly abused for malicious traffic.
The site presented a TLS certificate from Let’s Encrypt (certificate type YR1) that was valid at the time of capture, confirming that HTTPS was enabled. Gridinsoft assigned a trust score of 0 out of 100, and the domain appears on one external security blocklist, indicating that at least one security organization has flagged it. VirusTotal scans reported that eight out of ninety‑one antivirus engines flagged the domain, reinforcing the suspicion of malicious activity. The page title returned by the HTTP response was “ZE Express | Bebidas geladas”, a phrase that does not correspond to the advertised delivery service and may be used to lure Portuguese‑speaking victims.
The domain has been taken offline, and PhishDestroy currently lists it as blocked. No public evidence of the underlying phishing kit or specific payloads was observed, and the content of the landing page beyond the title has not been captured. Defenders should therefore treat the domain as high‑confidence malicious, add the FQDN and its resolving IP address to network‑level deny lists, monitor DNS queries for the associated nameservers, and continue to watch for re‑registration or the emergence of similar domains using the same hosting profile. Ongoing threat‑intel collection should include periodic re‑resolution of the IP, correlation with any new VirusTotal submissions, and verification against additional blocklist feeds.
네트워크 보안 인텔리전스
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | go-delivery-marmitex.shop |
phishing | Phishing Block |
| CIRA Canadian Shield DNS | go-delivery-marmitex.shop |
malicious | Sinkholed |
| Cloudflare DNS | go-delivery-marmitex.shop |
malicious | Sinkholed |
| Hagezi Threat Feed | go-delivery-marmitex.shop |
malicious | Sinkholed |
| DNS4EU | go-delivery-marmitex.shop |
malicious | Sinkholed |
위협 대응 Pipeline
공개 차단 목록 상태
저장된 캡처
도메인 인텔리전스
기술적 세부 사항DNS, SSL SAN, 타임스탬프
ICANN OVERSIGHT
인증 및 RAA 상황
인증 및 RAA 상황
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 분석
보관된 증거
사이트 성능 분석
Google PageSpeed Insights — mobile performance audit of go-delivery-marmitex.shop · checked Jun 27, 2026
증거 및 외부 보고서
PD-20260627-5099ED Recipient: abuse@prq.se 이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.