payme-paypal.com
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of payme-paypal.com
The domain payme-paypal.com appears to present itself as a PayPal-related payment page. Based on the page title, screenshot, and visible text in German, it claims that a user has received a payment request and prompts them to sign in to confirm the payment. The page uses PayPal branding elements and references official PayPal assets, which suggests it is designed to resemble a legitimate payment notification flow.
However, the domain name is not an official PayPal domain and closely resembles paypal.com while adding extra wording. The site does not appear to represent an independent business or service with its own clear identity; instead, it appears focused on imitating a branded payment experience. Based on the available content and scan context, this website may be intended to capture user credentials or payment-related information by leveraging familiarity with the PayPal brand.
Safety Assessment for payme-paypal.com
Several security signals indicate elevated risk at the time of this scan. The domain was flagged by 9 out of 91 security engines, with multiple detections describing it as phishing or malicious. In addition, the page closely resembles PayPal in both branding and wording, and the domain name itself closely resembles paypal.com, which may indicate a look-alike website intended to mislead visitors. The screenshot shows a login-related payment confirmation prompt, a common pattern associated with credential-harvesting pages.
Other contextual indicators also increase concern. The domain is newly registered at 0 days old, has no established traffic ranking, and a malware scan flagged the site’s own login URL and domain with a generic malicious classification. While major content-malice databases shown here were largely clean at the time of this scan, the domain's IP address is listed on one mail-reputation blocklist, and one additional blacklist source also listed the domain. Newly created phishing pages can sometimes appear before broader blocklist coverage catches up.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is served through Cloudflare infrastructure on IP address 104.21.24.214, with hosting geolocated to Canada based on available data. It presents a valid SSL/TLS certificate issued by Google Trust Services, expiring on 2026-09-24. DNSSEC appears to be enabled, and the domain uses Cloudflare nameservers. These are legitimate infrastructure features, but they should not be interpreted on their own as evidence of trustworthiness.
From a technical-risk perspective, the most notable concerns are the domain’s extremely recent registration date, the absence of an established traffic profile, and the presence of a flagged login page on a domain that visually imitates a well-known payment provider. The use of valid HTTPS and mainstream CDN-hosting components may simply help the page appear more convincing.
Share your experience with this website. Was it safe? Did you encounter any issues?