express-zedelivery[.]shop
“ZE Express | Bebidas geladas”
express-zedelivery.shop — Conteúdo indisponível. Representação da marca: Apple; Tipo de golpe: Impersonation. Resumo das evidências: VirusTotal 16/91 (alphaMountain.ai, BitDefender, Cluster25, CRDF, ESET); URLQuery 5 alerts; CF Radar malicious; PhishDestroy score 95/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain express-zedelivery.shop is currently active and has been identified as a high‑risk delivery‑scam operation. Infrastructure analysis shows the zone is delegated to ns1.dyna-ns.net and ns2.dyna-ns.net, and resolves to the IPv4 address 88.80.17.231. The domain is listed on one public security blocklist and has been actively blocked by the PhishDestroy service, indicating that at least one mitigation platform has taken preventive action.
VirusTotal scans report that three of ninety‑one antivirus engines flag the domain, confirming that automated detection tools have observed malicious characteristics, although the majority of engines have not yet generated a detection. No additional intelligence such as page title, SSL certificate details, or HTTP response codes is presently available, so the exact content served by the site remains unverified. Defenders should prioritize immediate containment: add express-zedelivery.shop and its resolving IP 88.80.17.231 to network‑level deny lists, configure DNS sink‑hole rules to intercept queries, and ensure that email security gateways block any messages containing links to this domain.
Continuous monitoring of the IP address for anomalous traffic patterns is advised, as the hosting provider may be reused for other malicious payloads. Security teams should also update intrusion‑detection signatures to include the observed nameserver pair and the specific domain string, and consider sharing the indicator set with threat‑intel sharing platforms to improve collective visibility. Given the active status and existing detections, the risk of user compromise remains elevated until the domain is fully neutralized.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | express-zedelivery.shop |
malicious | Sinkholed |
| CIRA Canadian Shield DNS | express-zedelivery.shop |
malicious | Sinkholed |
| Cloudflare DNS | express-zedelivery.shop |
malicious | Sinkholed |
| DNS4EU | express-zedelivery.shop |
malicious | Sinkholed |
| OpenDNS | express-zedelivery.shop |
phishing | Phishing Block |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Cruzamento de inteligência de ameaças · source references
Tecnologias · 4 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% de confiançaHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% de confiançaBigDataCloud IP Geolocation API provides detailed and accurate locality and security metrics of an IP address.
www.bigdatacloud.com 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Evidências arquivadas
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of express-zedelivery.shop · checked Aug 6, 2026
Evidências e relatórios externos
PD-20260806-4EA6F7 Recipient: abuse@dcs.net Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo