distribuidora-delivery[.]click
“ZE Express | Bebidas geladas”
distribuidora-delivery.click — 内容不可用. 证据摘要: VirusTotal 5/91 (alphaMountain.ai, Gridinsoft, Kaspersky, OpenPhish, SOCRadar); URLQuery 2 det.; PhishDestroy score 83/100. 注册商: Dynadot.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, distribuidora-delivery.click, is flagged as an active delivery scam infrastructure targeting customers of ZE Express, a beverage delivery service. Analysis of the page title 'ZE Express | Bebidas geladas' indicates an attempt to impersonate the legitimate ZE Express brand, likely to deceive victims into entering payment or personal details under false pretenses. No specific drainer kit signatures have been identified at this time, but the domain exhibits characteristics consistent with fraudulent order confirmation or fake delivery notification schemes. Infrastructure analysis reveals the following technical indicators: the domain was registered on June 26, 2026, through Dynadot, LLC, and currently resolves to the IP address 88.80.17.179. VirusTotal detection metrics show 3 out of 95 security vendors flagging the domain as malicious, suggesting early-stage detection with potential for increased scrutiny. The domain remains unlisted in Google Safe Browsing (GSB) at the time of this report, and no additional blocklist entries have been observed beyond the VirusTotal detections. The registration date, while seemingly in the future, may indicate either a typo or an attempt to evade automated detection systems that rely on domain age as a trust signal. As of the latest verification, distribuidora-delivery.click remains active and operational, posing a high risk to users who may encounter it through phishing emails, SMS messages, or malvertising campaigns. Immediate response actions are recommended, including browser-based blocking, network-level filtering of the IP address 88.80.17.179, and monitoring for related domains registered under the same infrastructure. Users should be advised to verify delivery notifications directly through official ZE Express channels and avoid entering credentials or payment details on unsolicited sites. The remaining risk is classified as high due to the domain's active status, minimal detection coverage, and targeted impersonation of a trusted brand.
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
证据与外部报告
PD-20260701-9B3EBE Recipient: abuse@dcs.net 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。