Ir para o relatório de segurança
⚠️
Este domínio foi sinalizado como malicioso
Mecanismos de segurança relatando uma detecção: 4. Tenha extremo cuidado – não insira credenciais ou informações pessoais.
Segurança de domínio e inteligência contra ameaças

pandatexprreess[.]today

“Panda Express - An American Chinese Restaurant”

Veredicto de ameaça Alto Pontuação de evidência 65/100
Disponibilidade Não verificado Nenhuma resposta atual conclusiva é armazenada
Detecções do VirusTotal: 4/91 Spamhaus DBL: DBL_PHISH
01/05/2026 1 Report Sent CDN
Resumo do relatório

pandatexprreess.today — Não verificado. Resumo das evidências: VirusTotal 4/91 (Fortinet, Gridinsoft); URLQuery 1 det.; Spamhaus DBL_PHISH; PhishDestroy score 65/100. Registrador: NiceNIC.

A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.

Resumo das evidências
ALTO
Ref.
B1787360
Pontuação
65/100

PhishDestroy identifies pandatexprreess.today as an active DHL-branded phishing domain designed to harvest cryptocurrency wallet credentials and drain victim funds. This impostor platform mirrors the legitimate DHL Express service interface to deceive users into entering private wallet keys or connecting crypto wallets under the pretense of shipping fee reconciliation. The draineer kit observed on the landing page is configured to intercept Ethereum, Solana, and Bitcoin wallet connections and transmit seed phrases or private keys to attacker-controlled servers. No specific drainer-as-a-service identifier has been extracted at this stage; however, the payload structure aligns with recent modular phishing kits such as SpinDrainer and EtherHiding variants that obfuscate JavaScript via Base64 and employ WebSocket communication to exfiltrate credentials in real time.

This domain was flagged on April 25, 2026, resolving to AS13335 (Cloudflare, Inc.) on IP 104.21.4.125. The domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED with a creation date of April 24, 2026, indicating a rapid deployment campaign. VirusTotal currently reports 4/95 detection engines flagging the URL, and the SSL certificate is issued by Let’s Encrypt (valid until July 23, 2026). Google Safe Browsing (GSB) has not yet flagged the domain, and third-party blocklist aggregation via URLScan and PhishTank shows zero current listings. Registrant privacy is enabled, and name servers point to Cloudflare’s infrastructure (dina.ns.cloudflare.com, ray.ns.cloudflare.com), a common tactic to evade takedowns and geofencing.

The domain remains active and continues to resolve without blocklisting, suggesting the threat actor is operating with low detection visibility. Immediate mitigation includes blacklisting the domain at DNS and network levels and reporting to CERT teams and browser vendors for GSB inclusion. Users are strongly advised to verify sender domains in unexpected shipping notifications, avoid clicking links in unsolicited emails, and use hardware wallets or air-gapped signing for crypto transactions. The current risk level is assessed as HIGH due to the active draineer payload, lack of detection coverage, and the high-value target (crypto wallets). PhishDestroy continues monitoring for infrastructure shifts and payload evolution, with a recommendation to prioritize takedown within 24 hours to mitigate further victimization.

VirusTotal
VirusTotal
4 det.
URLQuery
URLQuery
1 det.
URLScan
URLScan
Certificado TLS
Let's Encrypt
Idade
4 mo
Status observado
Não verificado
PhishDestroy
DestroyList
Listado
Reports Sent
1
Cobertura dos dados VirusTotal 4 / 91 URLQuery 1 det. PhishStats checked — no match recorded OTX no community references CF Radar scan completed URLScan capture relatório armazenado URLScan verdict Análise concluída Bloqueios de DNS 14 verificado — sem bloqueios TLS valid certificate, 82d WHOIS 4 mo old Captura de tela 3 captures · 3 sources Cadeia de redirecionamentos não investigado
Inteligência de segurança de rede Registrar context
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation

Pipeline de resposta a ameaças

Descoberta
Checks
Reports
Disponibilidade
11/12
Sent Report Recorded
Stored sent-report record for registrar NICENIC INTERNATIONAL GROUP CO., LIMITED, hosting provider, 1 abuse contact
abuse@nicenic.net
01/05/2026

Status da lista de bloqueios pública

Captura armazenada

Título da página
Panda Express - An American Chinese Restaurant
Certificado TLS
Valid transport encryption · Emitido por Let's Encrypt · valid for 82 days

Inteligência de Domínios

Domínio
URLScan Verdict Análise concluída score 0 report ↗
Servidor / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden A reputação do Edge-IP não é atribuída a este domínio.
Endereço IP 104.21.4.125 CDN
LocalizaçãoCA Toronto, CA
RedeAS13335 · Cloudflare, Inc.
O IP de origem está oculto atrás de um proxy CDN. Os resultados de IP reverso para o endereço de borda contêm locatários não relacionados; encontrar a origem requer DNS passivo ou dados de transparência de certificado.
RegistroCriado 24/04/2026 (117d) Expires 24/04/2027
Elapsed Since First Report 5h
O que contabilizamos Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Não verificado.
O que cada relatório contém Os registros de relatórios de saída armazenados podem fazer referência a evidências disponíveis no momento, como veredictos de fornecedores, dados de registro, detalhes de hospedagem, classificações ou capturas de tela. Esta página não infere a carga exata entregue, recebimento, confirmação ou ação de um destinatário.
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
Detectado pela primeira vez01/05/2026
IoC Extractionscanned 01/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttps://pandatexprreess.today/
Servidores de nomesgarrett.ns.cloudflare.comraphaela.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 24/04/2026scanned 01/05/2026
Case ID
ICANN OVERSIGHT

Credenciamento e contexto RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Nada é enviado automaticamente.

Latest Classified Outcome 2026-08-19 03:15:15 UTC

Primary outcome Registration hold observed reason: Registrar clientHold 95% confidence
Attribution NICENIC INTERNATIONAL GROUP CO., LIMITED mechanism: Registrar clientHold source: Rdap Status Collector
Evidence layers Availability: DNS inactive Content: Unreachable DNS: NXDOMAIN Registration: Registrar clientHold
Latest HTTP observation Desconhecido Origin unreachable Http 5xx 20% 2026-08-19 02:33:22 UTC
RDAP registration Registrar clientHold NICENIC INTERNATIONAL GROUP CO., LIMITED · IANA 3765 RDAP HTTP 200 source: Rdap Status Collector clientDeleteProhibitedclientHoldclientTransferProhibited expires 2027-04-24 13:00:30 UTC checked 2026-08-19 03:15:15 UTC
Registrar action marker verified clientHold marker NICENIC INTERNATIONAL GROUP CO., LIMITED · IANA 3765 causal link to our report not established
Observed timeline last reachable: 2026-06-17 16:29:49 UTC current episode first observed: 2026-08-05 01:45:38 UTC observed RIP window: 2026-06-17 16:29:49 UTC → 2026-08-05 01:45:38 UTC · 1,161.26h midpoint estimate ≈ 2026-07-11 21:07:43 UTC · precision very low · basis bounded
Availability, content, DNS and registration are independent evidence layers. NXDOMAIN, an unreachable origin or missing content alone does not prove registrar action. A registrar or provider is credited only when a direct technical marker identifies that actor. Report causality is shown separately.
Tecnologias · 22 identified
Drupal
CMS

Drupal is a free and open-source web content management framework.

www.drupal.org 100% de confiança
MariaDB
Databases

MariaDB is an open-source relational database management system compatible with MySQL.

mariadb.org 100% de confiança
Node.js
Programming languages

Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.

nodejs.org 100% de confiança
PHP
Programming languages

PHP is a general-purpose scripting language used for web development.

php.net 100% de confiança
Varnish
Caching

Varnish is a reverse caching proxy.

www.varnish-cache.org 100% de confiança
Nginx
Web servers Reverse proxies

Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.

nginx.org 100% de confiança
Amazon Web Services
PaaS

Amazon Web Services (AWS) is a comprehensive cloud services platform offering compute power, database storage, content delivery and other functionality.

aws.amazon.com 100% de confiança
Pantheon
PaaS

Pantheon is a WebOps (Website Operations) and Management Platform for WordPress and Drupal.

pantheon.io 100% de confiança
Express
Web frameworks Web servers

Express is a web application framework for Node.js, released as free and open-source software under the MIT License. It is designed for building web applications and APIs.

expressjs.com 100% de confiança
Fastly
CDN

Fastly is a cloud computing services provider. Fastly's cloud platform provides a content delivery network, Internet security services, load balancing, and video & streaming services.

www.fastly.com 100% de confiança
Typekit
Font scripts

Typekit is an online service which offers a subscription library of fonts.

typekit.com 100% de confiança
Quantum Metric
Analytics

Quantum Metric is a continuous product design platform that helps organizations build better products faster.

www.quantummetric.com 100% de confiança
OneTrust
Cookie compliance

OneTrust is a cloud-based data privacy management compliance platform.

www.onetrust.com 100% de confiança
ipify
Geolocation

ipify is a service which provide public IP address API, IP geolocation API, VPN and Proxy detection API products.

ipify.org 100% de confiança
Google Tag Manager
Tag managers

Google Tag Manager is a tag management system (TMS) that allows you to quickly and easily update measurement codes and related code fragments collectively known as tags on your website or mobile app.

www.google.com 100% de confiança
DataDome
Segurança

DataDome is a cybersecurity platform that specialises in bot protection and mitigation, offering advanced solutions to safeguard websites and mobile applications against malicious bot traffic, credential stuffing, scraping, and other automated threats.

datadome.co 100% de confiança
crypto-js
JavaScript libraries

crypto-js is a JavaScript library of crypto standards.

github.com 100% de confiança
cdnjs
CDN

cdnjs is a free distributed JS library delivery service.

cdnjs.com 100% de confiança
Cloudflare Browser Insights
Analytics RUM

Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.

www.cloudflare.com 100% de confiança
Cloudflare
CDN

Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.

www.cloudflare.com 100% de confiança
Amazon CloudFront
CDN

Amazon CloudFront is a fast content delivery network (CDN) service that securely delivers data, videos, applications, and APIs to customers globally with low latency, high transfer speeds.

aws.amazon.com 100% de confiança
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org 100% de confiança
Detected via Cloudflare Radar · Wappalyzer engine
Denunciar este domínio Envie evidências e ajude a proteger outras pessoas

Análise do VirusTotal

4 / Os fornecedores de segurança 91 sinalizaram este domínio
View on VT
Last analyzed
Fortinet
Gridinsoft

Evidências e relatórios externos

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260501-A3A26A Recipient: abuse@nicenic.net, abuse@identitydigital.com
Page title stored with report: Order Panda Express | A Fast Casual Chinese Restaurant | Panda Express Chinese Restaurant
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 42.6 KB

Você foi afetado por este site?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.

Europol
Encontre o canal de denúncia oficial do seu país da UE
National police directory
Cuidado com os golpistas que prometem recuperação! Os criminosos podem entrar em contato novamente com as vítimas fingindo ser investigadores, advogados ou agentes de recuperação. Não pague taxas antecipadas nem compartilhe credenciais. Saiba mais sobre fraudes relacionadas à recuperação →

Notifique as autoridades locais

Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.

Diretório de 97 países
Rascunho assistido por IA – os detalhes do incidente são processados pelo provedor de IA Revise e envie você mesmo

Verificar qualquer domínio

Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública

Digitalize agora

Denunciar phishing

Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade

Denunciar

Feed de ameaças em tempo real

Relatórios recentes de phishing e alterações de disponibilidade observadas

Monitorar

Mantenha-se informado, mantenha-se seguro

Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo

Feed de ameaças em tempo real Recorrer deste anúncio
HTML · IFRAME

Incorporar este relatório

Compartilhe essas informações sobre ameaças em seu site ou blog

embed.html
<iframe
  src="https://phishdestroy.io/pt-br/embed/domain/pandatexprreess.today"
  title="PhishDestroy threat report for pandatexprreess.today"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Uma carta de agradecimento muito sincera

Gerador de rascunho satírico

Destinatário
Contexto das taxas

Rascunho satírico. Os valores das taxas são estimativas; não se afirma que sejam atribuíveis exatamente a este domínio.