MALICIOUS — CRITICAL
paypalsupport.pages.dev Safety Check — PayPal Brand Impersonation
paypalsupport[.]
This domain, paypalsupport.pages.dev, is flagged as a high-risk brand impersonation threat targeting PayPal users.
- VirusTotal
- 11/91
- Blocklists
- No stored match
- Kullanılabilirlik
- Bilinen son aktif · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
paypalsupport.pages.dev — Bilinen son aktif (HTTP 200). Marka kimliğine bürünme: PayPal; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 11/91 (alphaMountain.ai, Bfore.Ai PreCrime, BitDefender, CyRadar, ESET); PhishDestroy score 98/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
This domain, paypalsupport.pages.dev, is flagged as a high-risk brand impersonation threat targeting PayPal users. Analysis indicates the infrastructure is designed to mimic official PayPal support pages, likely to harvest credentials or facilitate unauthorized transactions. The page title, pay.pal.support, reinforces the deception by closely resembling legitimate PayPal subdomains, increasing the likelihood of victim engagement. Infrastructure analysis reveals the domain resolves to the IP address 188.114.97.3, associated with Cloudflare, Inc. and located in Canada. The domain was registered on March 24, 2026, through Cloudflare’s registrar services. Security vendor assessments on VirusTotal report 11 detections out of 95, while the domain appears on one security blocklist. The SSL certificate is issued by Google Trust Services (WE1), a common feature in both legitimate and malicious Cloudflare-hosted pages. Google Safe Browsing does not currently list the domain, though this may reflect delayed detection rather than absence of threat. As of the latest verification, paypalsupport.pages.dev remains active, continuing to pose a risk to users who may mistake it for legitimate PayPal support. Response actions should include immediate reporting to hosting providers and certificate authorities to facilitate takedown. Organizations are advised to block the domain and associated IP at the network level, while end users should be cautioned against interacting with any unsolicited communications directing them to this infrastructure. The remaining risk is classified as high due to the domain’s active status and the potential for credential theft or financial fraud.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Veri kapsamı13 recorded checks
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 6 identified
Open-source CMS powering over 40% of websites worldwide.
Open-source relational database management system.
Server-side scripting language designed for web development.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of paypalsupport.pages.dev · checked Mar 24, 2026
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.