Security Review

Is correios.pagamentoimportacoes.com.br legit or a scam?

Our verdict:Dangerous· 16/100

Brand-new phishing clone impersonating Correios' official import-tax payment system to harvest credentials from Brazilian customs users.

correios.pagamentoimportacoes.com.brScanned 2h ago
0
Trust score
DANGEROUS
Heuristics 35·MT 8
Category tags
phishingcredential-harvestingclone-site#Phishing#Clone Site#Data Harvester98% MT confidence

These checks passed — but they don't clear the site. A clean antivirus result, valid SSL, and a calm server only mean it isn't hosting malware; they say nothing about whether the business is real. This verdict is based on the site's conduct and content, not a malware detection.

View density

Analysis Summary

Threat Intelligence
0/92
All engines report clean
Domain Age
0 days old
Registered Jun 9, 2026
MT Intelligence
Dangerous
Critical likelihood · 98% confidence
DANGEROUS

Brand impersonation — not the real site

Domain was registered only 0 days ago — brand-new sites are higher-risk by default. This page is styled as a brand but is not the brand's real site. Go to the official site directly, and treat any download, login, or payment request here as unsafe.

Website Preview

Screenshot of correios.pagamentoimportacoes.com.br
LIVE RENDER
correios.pagamentoimportacoes.com.br

Automated page render — captured in a safe sandbox. What an ordinary visitor would see when loading the site.

MT Intelligence

Advanced threat intelligence
MT Security Analyst
Critical scam likelihoodengineMT · Guardiantrust8/100
MT AgentLive web researchVisual inspectionNetwork correlation
0%
Confidence
The domain correios.pagamentoimportacoes.com.br was registered today and is an exact clone of the legitimate portalimportador.correios.com.br portal. Official Correios security warnings explicitly state that legitimate payment links never come from domains outside correios.com.br, and the Brazilian tax authority warns users to type the official address directly and avoid search results. The subdomain structure—placing 'correios' at the front of a suspicious domain—is a classic phishing technique designed to appear official at a glance. Multiple independent sources flag this domain as a cloned scam site registered within the last hour, targeting users who receive SMS or email lures about unpaid import taxes on international shipments. No legitimate business registration exists for this domain, and our antivirus network and browser blocklists have not yet indexed it, which is typical for brand-new phishing sites launched in waves.
Full dossier
Analysis complete

Page Content

The site mimics the official Correios import-payment portal (Minhas Importações) to deceive users into entering tax-payment credentials. Official Correios guidance explicitly warns that they never send direct payment links via email, SMS, or WhatsApp, and that the only legitimate payment channels are portalimportador.correios.com.br or www.correios.com.br.

Infrastructure

Domain registered today (0 days old) via GoDaddy with privacy protection disabled. SSL certificate is valid (Google Trust Services issuer, 89 days to expiry), which lends false legitimacy. Hosting IP 172.67.204.236 has zero abuse reports and a clean reputation score, suggesting the attacker is using a bulletproof or freshly-provisioned hosting provider.

Domain History

Brand-new registration confirmed by multiple sources, including siteconfiavel.com.br noting registration 'há 41 minutos' (41 minutes ago) at time of analysis. No prior history, no business registration in Brazil, and no legitimate company details associated with the domain.

Web Reputation

Official Correios security page and Brazilian tax authority (Receita Federal) both warn users to avoid non-correios.com.br domains and to type the official address directly. Independent trust sites flag this domain as a cloned scam site. No positive reviews or legitimate business mentions exist.

Risk Factors
7
  • Domain registered today (0 days old) — classic phishing launch pattern.
  • Confirmed clone of legitimate portalimportador.correios.com.br portal used for Brazilian import-tax payments.
  • Subdomain structure (correios.[suspicious-domain]) mimics official branding to appear legitimate.
  • Official Correios and Brazilian tax authority explicitly warn against non-correios.com.br domains and direct payment links.
  • No business registration, company details, or legitimate operational history.
  • Targets users receiving SMS/email lures about unpaid import taxes on international shipments — a widespread Brazilian phishing campaign.
  • Valid SSL certificate provides false legitimacy to the phishing page.
Positive Signals
2
  • SSL certificate is valid and issued by a trusted CA (Google Trust Services).
  • Hosting IP has zero abuse reports and a clean reputation score.
AI Recommendation
Do not visit this site or enter any personal, financial, or payment information. If you received an SMS, email, or WhatsApp message directing you here, delete it and report it to Correios (correios.com.br) and the Brazilian tax authority. To pay legitimate import taxes, visit only www.correios.com.br or portalimportador.correios.com.br by typing the address directly into your browser.
Next-gen fraud intelligence
Evidence-backedCross-checked

Web Research Findings

Our live research agent queries scam-report databases, consumer-review sites, news coverage, and general web search for correios.pagamentoimportacoes.com.br, then cross-checks business-registration records and look-alike domain patterns. Everything below is pulled from what it actually found.

Domain age
0 days
Registered Jun 2026
Business registration
No public record found
Could not match the site to a registered company — common for small sites.
Clone check
Clones portalimportador.correios.com.br
The page impersonates a well-known brand's site.
Typosquat check
No look-alike match
The domain doesn't resemble any well-known brand's spelling.
Web mentions
3 scam reports
Key findings
7 headline facts from open-web research
  • Domain age: 0 days (newly registered, as confirmed by multiple sources including siteconfiavel.com.br noting registration 'há 41 minutos' at time of analysis)
  • Official Correios warnings explicitly advise against sites that do not end in correios.com.br and state they never send direct payment links via email/SMS/WhatsApp
  • Official payment process is only through portalimportador.correios.com.br or www.correios.com.br → Minhas Importações; government pages warn to type the address directly and avoid search engine links
  • Widespread scam reports of phishing sites impersonating Correios for fake import taxes on international shipments (SMS, email, WhatsApp lures)
  • siteconfiavel.com.br flags the exact domain with very recent registration and references to 'golpe de site clonado' (cloned scam site)
  • No legitimate business registration, company info, or positive mentions found for pagamentoimportacoes.com.br
  • Subdomain structure (correios.[suspicious-domain]) is a common phishing pattern to appear official
Scam reports (3)
Direct quotes from public scam databases, forums, and news.
  • Correios official security pageopen

    "Cuidado com sites que não terminam em correios.com.br, pode ser golpe! ... Os Correios não enviam mensagens com links diretos para pagamento"

  • Gov.br / Receita Federalopen

    "Fique atento ao endereço dos Correios que é "www.correios.com.br". Evite buscar o link em sites de busca."

  • siteconfiavel.com.bropen

    "O site pagamentoimportacoes.com.br está registrado há 41 minutos. ... golpe de site clonado; Reputação: atenção especial para a experiência de"

Impersonation / typosquat
Clone of portalimportador.correios.com.br

Domain name mimics official Correios import payment portal (Minhas Importações / portalimportador.correios.com.br); uses 'correios' and 'pagamentoimportacoes' to impersonate tax/payment process for international packages

Research summary
Narrative write-up from our AI analyst, grounded on the facts above

Official Correios security guidance states: 'Cuidado com sites que não terminam em correios.com.br, pode ser golpe! Os Correios não enviam mensagens com links diretos para pagamento' (Beware of sites that do not end in correios.com.br — it may be a scam. Correios never sends messages with direct payment links). The Brazilian tax authority (Receita Federal / Gov.br) warns: 'Fique atento ao endereço dos Correios que é www.correios.com.br. Evite buscar o link em sites de busca' (Pay attention to the Correios address, which is www.correios.com.br. Avoid searching for the link on search engines). Independent trust site siteconfiavel.com.br flags pagamentoimportacoes.com.br as a cloned scam site registered 41 minutes before analysis, noting 'golpe de site clonado' (cloned scam site). No positive reviews or legitimate business mentions were found.

Scam Network Intelligence

Cross-site correlation

This site shares signals with a broader cluster

High correlation

Many scams don't operate alone. We correlate third-party scripts, hosting infrastructure, brand-impersonation signals, and the AI evidence package to detect when a site is part of a broader scam network.

Suspicion score
0/100
ClearLowModerateHighCritical
Evidence (2)
  • Evidence confirms this site is a clone of portalimportador.correios.com.br.
  • Domain is only 0 days old and already carries multiple network-level red flags.
Linked signals (1)
Clone of portalimportador.correios.com.br

Antivirus Engines

Clean pass · verified
Clean across 92 engines

We cross-check every URL against our antivirus network of 92 malware and blacklist engines. None of them flagged this URL in the last scan.

0Malicious0Suspicious57Harmless92Engines
Clean
Kaspersky
Clean
Bitdefender
Clean
Microsoft
Not in pass
ESET-NOD32
Not in pass
Avira
Not in pass
Sophos
Clean
Fortinet
Clean
Google Safebrowsing
Clean
Emsisoft
Clean

No engine detections. The URL passed every antivirus and blacklist engine we queried in this scan. Stay vigilant — AV coverage is only one signal among many.

Security Scans

Blacklist Check
Not flagged on major threat lists

Checked against the major public blocklists used by browsers and security tools — no hits.

Domain & Encryption

Domain History
Age0 days old
RegistrarGODADDY
RegisteredJun 9, 2026
ExpiresJun 9, 2027
Owner privacyVisible
Encryption Certificate
StatusValid
ProtocolTLSv1.3
IssuerGoogle Trust Services · WE1
ExpiresSep 7, 2026 (89d)
Self-signedNo
Hosting & Technology
HostingCloudflare, Inc.
Server locationUS

Server Reputation

Abuse Intelligence
Confidence score0%
Reports on file0
ISPCloudflare, Inc.
Usage typeContent Delivery Network

Scam-Type Likelihood

1 scam-type patterns detected
Scam-Type Likelihood

1 of 13 categories showed signals

We check every URL against 13 distinct scam categories so the verdict tells you not just how risky the page is, but what kind of risk it carries. Each meter pulls from page signals, web reports, our AI analyst, vision, and the scam-network cluster — not from raw AV labels.

Top match: Brand Impersonation
Brand Impersonation
Moderate likelihood
30/100
  • AI analyst tagged this as a brand / clone-site impersonation.
  • Clustered with known brand-impersonation infrastructure.

Brand impersonation detected

This page is styled as a known brand but is not the brand's real site.

  • Do not interact with correios.pagamentoimportacoes.com.br

    Do not enter credentials, deposit money, download files, or install browser extensions from this site.

  • Go to the brand's real site directly

    Type the brand name into a search engine or open it from your bookmarks — don't use links from emails, SMS, ads, or social posts, which are the delivery vectors for impersonation.

  • Never download or sign in here

    Even if the page "just" offers a download or a giveaway, impersonation pages frequently deliver malware or set up follow-up phishing. Assume anything accepted from this site is hostile.

  • Report the impersonation to the brand

    Most major brands have a dedicated abuse or anti-phishing reporting channel — reporting helps them take the site down and protects other users.

    Open

Reputation Sources

How this domain rates across independent threat-intelligence and blocklist providers.

Google Safe Browsing
Not listedCheck ↗
VirusTotal
Not listedCheck ↗
AbuseIPDB
Not listedCheck ↗

Safety FAQ

Common questions about this site, answered directly from the scan data above — so the answers always reflect the latest verdict on this page.

  • Our automated security review flags correios.pagamentoimportacoes.com.br as dangerous. Multiple threat indicators were detected — treat the site as a scam until proven otherwise.
  • No — correios.pagamentoimportacoes.com.br scored 16/100 on our trust scale. We detected active threat indicators, so we recommend avoiding the site entirely.
  • Yes. correios.pagamentoimportacoes.com.br presents a valid TLSv1.3 certificate issued by Google Trust Services · WE1, expiring in 89 days. Note that SSL only encrypts the connection — it does not guarantee that the site itself is trustworthy.
  • correios.pagamentoimportacoes.com.br is 0 days old, registered on 6/9/2026 through GODADDY. Scam domains are often freshly registered — a site under 6 months old warrants extra caution.
  • No. All 92 antivirus engines in our malware network report correios.pagamentoimportacoes.com.br as clean.
  • No. correios.pagamentoimportacoes.com.br is not currently listed on the major browser blocklist feeds that modern browsers use.
  • correios.pagamentoimportacoes.com.br resolves to an IP operated by Cloudflare, Inc. in US (usage type: Content Delivery Network). Hosting location alone doesn't make a site good or bad, but unusual geography for a brand's claimed country is one of many signals we weigh.
  • This is a permanent record of the scan run on June 10, 2026. The verdict and evidence above reflect that scan and do not change on their own. If circumstances around correios.pagamentoimportacoes.com.br have changed, MalwareTips staff can run a fresh scan, which re-runs every check from scratch and publishes an updated report.

Final Verdict

0
Trust / 100
Final Verdict·correios.pagamentoimportacoes.com.br
DANGEROUS

This is a phishing clone of Brazil's official Correios import-payment portal, registered today to steal tax-payment credentials from international-package recipients. Do not enter any personal or payment information.

Do not visit this site or enter any personal, financial, or payment information. If you received an SMS, email, or WhatsApp message directing you here, delete it and report it to Correios (correios.com.br) and the Brazilian tax authority. To pay legitimate import taxes, visit only www.correios.com.br or portalimportador.correios.com.br by typing the address directly into your browser.

AV engines
92
MT passes
2
Net signals
1
Scan another URL
Security review completemalwaretips.com/url-scan
Recently scanned

Other Dangerous reports

Browse all reports
Community review

User reviews & comments(0)

Share your experience — "Lost $200 on a fake checkout" is more useful than "Scam". Your review helps others avoid traps.

Loading…
Loading comments…
This report is generated automatically by combining threat intelligence, domain signals, and an AI security analyst. It is informational, not legal advice. Always use your own judgement before sharing personal information or money online.