paypal-login[.]de
“paypal-login.de”
paypal-login.de — 隐形 · 可达. 品牌冒充:PayPal; 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 17/91 (ADMINUSLabs, alphaMountain.ai, Bfore.Ai PreCrime, BitDefender, Chong Lua Dao); URLQuery 8 alerts; Spamhaus DBL_PHISH; cloaking observed; PhishDestroy score 100/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy has identified paypal-login.de as an elevated risk phishing site engaged in brand impersonation of PayPal. This domain is actively being used to deceive users into entering their sensitive login credentials on a fraudulent interface that mimics PayPal's official sign-in page. The threat is classified as a fake login attack, specifically targeting PayPal customers, and is currently active and operational. Users who encounter this site risk having their account credentials stolen and potentially their financial information compromised.
Technical analysis of paypal-login.de reveals several red flags that confirm its malicious nature. The domain was registered on April 28, 2026, which is very recent, a common tactic used by cybercriminals to avoid detection. It is hosted on IP address 144.76.59.138, and its SSL certificate is issued by Let's Encrypt (R12), which provides a false sense of security. On VirusTotal, 16 out of 95 security vendors flag this domain as malicious, and it appears on one security blocklist. The site's page title is simply 'paypal-login.de,' lacking any legitimate branding, and it resolves to a server likely controlled by threat actors.
To protect against this specific phishing threat, users should never enter their PayPal credentials on any site other than the official PayPal domain (paypal.com). Always verify the URL in the address bar before logging in, and enable two-factor authentication on your PayPal account for an added layer of security. If you have already submitted information on this fraudulent site, change your PayPal password immediately and contact PayPal support to report the incident. PhishDestroy recommends using a reputable password manager to automatically detect and avoid phishing sites, and to regularly monitor your account for unauthorized transactions.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | s.cdn-fileserver.com |
malicious | Sinkholed |
| Quad9 DNS | s.cdn-fileserver.com |
malicious | Sinkholed |
| DigiCert UltraDNS | l.cdn-fileserver.com |
malicious | Sinkholed |
| Quad9 DNS | l.cdn-fileserver.com |
malicious | Sinkholed |
| Hagezi Threat Feed | findresultshub.com |
malicious | Sinkholed |
| Quad9 DNS | findresultshub.com |
malicious | Sinkholed |
| Quad9 DNS | paypal-login.de |
malicious | Sinkholed |
| DNS4EU | paypal-login.de |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of paypal-login.de · checked Apr 28, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。