deliveryexpress[.]sa[.]com
“deliveryexpress.sa.com - Transport & Logistics Service”
Detecção armazenada
Alerta de cloaking
- Tipo de cloaking
status_split- Pontuação de cloaking
- 2/6
Resumo das evidências
On July 22, 2026 analysts observed that the domain deliveryexpress.sa.com is currently offline but was previously identified as a brand impersonation conduit targeting Google. The site was taken down and blocked by the PhishDestroy sinkhole, indicating that active mitigation has been applied. Technical examination shows the domain resolves to IP address 185.255.122.94, which is hosted in Ukraine and belongs to AS30860 operated by Virtual Systems LLC. No SSL certificate was presented, meaning all traffic would have been unencrypted, a common characteristic of low‑cost impersonation campaigns. Nameserver records list ns1.centralnic.net, ns2.centralnic.net, ns3.centralnic.net, and ns4.centralnic.net, all pointing to the CentralNic registry infrastructure.
The registrar for the domain is Sav.com, LLC, suggesting the registration was performed through a commercial registrar rather than a privacy‑protected service. The page title returned by the HTTP response is "deliveryexpress.sa.com - Transport & Logistics Service," which does not reference Google and provides no immediate indication of the intended brand abuse. Gridinsoft assigned a trust score of 0 out of 100, reflecting a highly malicious reputation. The domain appears on a single security blocklist, and VirusTotal reports indicate the domain was scanned by 95 vendors without any detections, a result that should not be interpreted as confirmation of safety.
The primary uncertainty lies in the exact content that was served before the takedown; no screenshots or login pages have been recovered, and the specific phishing kit or credential‑stealing mechanisms remain unknown. Defenders should continue to block the domain at perimeter filters, monitor the associated IP range for any resurgence, and add the domain to internal blacklists. Further investigation of the hosting provider and any related domains sharing the same nameserver set may reveal additional infrastructure used in the campaign.
Data Coverage
Sinais de segurança
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
Status do domínio
Acessível → Inacessível
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
-
Status do domínio
Inacessível → Acessível
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo