deliveryexpress[.]sa[.]com
“deliveryexpress.sa.com - Transport & Logistics Service”
Збережене виявлення
Виявлено маскування
- Тип маскування
status_split- Оцінка маскування
- 2/6
Зведення доказів
On July 22, 2026 analysts observed that the domain deliveryexpress.sa.com is currently offline but was previously identified as a brand impersonation conduit targeting Google. The site was taken down and blocked by the PhishDestroy sinkhole, indicating that active mitigation has been applied. Technical examination shows the domain resolves to IP address 185.255.122.94, which is hosted in Ukraine and belongs to AS30860 operated by Virtual Systems LLC. No SSL certificate was presented, meaning all traffic would have been unencrypted, a common characteristic of low‑cost impersonation campaigns. Nameserver records list ns1.centralnic.net, ns2.centralnic.net, ns3.centralnic.net, and ns4.centralnic.net, all pointing to the CentralNic registry infrastructure.
The registrar for the domain is Sav.com, LLC, suggesting the registration was performed through a commercial registrar rather than a privacy‑protected service. The page title returned by the HTTP response is "deliveryexpress.sa.com - Transport & Logistics Service," which does not reference Google and provides no immediate indication of the intended brand abuse. Gridinsoft assigned a trust score of 0 out of 100, reflecting a highly malicious reputation. The domain appears on a single security blocklist, and VirusTotal reports indicate the domain was scanned by 95 vendors without any detections, a result that should not be interpreted as confirmation of safety.
The primary uncertainty lies in the exact content that was served before the takedown; no screenshots or login pages have been recovered, and the specific phishing kit or credential‑stealing mechanisms remain unknown. Defenders should continue to block the domain at perimeter filters, monitor the associated IP range for any resurgence, and add the domain to internal blacklists. Further investigation of the hosting provider and any related domains sharing the same nameserver set may reveal additional infrastructure used in the campaign.
Data Coverage
Сигнали безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
Хронологія виявлення
-
Статус домену
Доступний → Недоступний
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
-
Статус домену
Недоступний → Доступний
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога