purolator[.]packagevm[.]vip
purolator.packagevm.vip — İçerik kullanılamıyor. Marka kimliğine bürünme: Google. Kanıt özeti: VirusTotal 13/91 (BitDefender, Chong Lua Dao, CRDF, CyRadar, Forcepoint ThreatSeeker); Google Safe Browsing flagged; Spamhaus DBL_PHISH; PhishDestroy score 89/100. Kayıt kuruluşu: Gname.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain is flagged as a high-risk delivery scam targeting Purolator brand. Analysis of the available evidence shows multiple indicators of malicious intent. The domain was registered on October 04, 2025, through Gname.com Pte. Ltd., a registrar often associated with disposable or high-risk domains. VirusTotal detection is significant: 13 of 91 security vendors flag this domain as malicious or suspicious. Google Safe Browsing specifically flags it for social engineering, which aligns with the delivery scam classification.
The domain appears on at least one security blocklist and is actively blocked by PhishDestroy, a phishing protection service. The domain name itself leverages the legitimate Purolator brand by inserting 'purolator' followed by 'packagevm.vip', a structure commonly seen in brand impersonation scams that trick users into believing they are visiting a legitimate package tracking site. The domain creation date of October 04, 2025, combined with the report date of July 29, 2026, indicates it has been active for approximately 10 months. The exact page content and infrastructure details such as ASN, hosting IP, and SSL certificate status are not available in the current intelligence, so the specific scam mechanism (e.g., credential harvesting, malware delivery, or payment theft) cannot be confirmed.
Defenders should treat this domain as actively malicious. Recommended actions include blocking the domain at network and email gateways, adding it to threat intelligence feeds, and monitoring for related domains using the same naming pattern. Users should be warned not to interact with any messages or links referencing purolator.packagevm.vip. Further investigation is warranted to identify the hosting infrastructure and any associated domains for broader takedown efforts.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Registration: packagevm.vip
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For the registrable domain packagevm.vip behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin