In this article I explain how you can remove unwanted notifications in the form of pop-ups from Ppwpn.com.
Ppwpn.com is a fraudulent website that is used by cybercriminals to deceive people.
The deception takes place by displaying a prompt to accept notifications. An example of this can be seen below:
If you accept this prompt by clicking on ‘Allow’, a pop-up will be displayed on your computer.
In reality, these pop-ups are notifications that are sent by the browser. Also known as push notifications.
These push notifications then appear as warnings, offers, or other important messages but are intended to entice you to click on unsafe links or enter personal data.
In this article I explain how you can remove these annoying pop-ups and prevent Ppwpn.com from obtaining permission to send notifications again.
Scam Domain Risk Report
ppwpn.com
https://ppwpn.com/
Executive Summary
This scam-domain assessment summarizes technical trust indicators, blacklist checks, infrastructure signals, and visible fraud patterns for ppwpn.com.
This domain shows meaningful risk indicators, although some stabilizing trust signals are also present.
Risk score 57/100, trust score 29/100.
Key Findings
Multiple engines flag this domain as suspicious or malicious.
The site does not present a valid SSL/TLS certificate.
The domain has existed for a longer period of time.
The reviewed URL was not found in the checked browser safety data.
No public malware delivery match was found for this host.
Score Overview
Core Risk Scores
Security And Infrastructure
Transparency Snapshot
Domain Profile
The table below summarizes the key domain profile data points captured during this domain investigation.
| Domain | ppwpn.com |
|---|---|
| Registration Date | 2019-08-13T21:47:25Z |
| Age | 2589 days |
| Registrar | GoDaddy.com, LLC |
| Expiry Date | 2027-08-13T21:47:25Z |
| Nameservers | ns32.domaincontrol.com, ns31.domaincontrol.com |
| IP | 3.33.130.190 |
| ASN | AS16509 Amazon.com, Inc. |
| Provider | AS16509 Amazon.com, Inc. |
| Country | US |
| CDN / Proxy | No clear indication |
| DNSSEC | Not directly determined |
SSL/TLS
The table below summarizes the key ssl/tls data points captured during this domain investigation.
| HTTPS | No |
|---|---|
| Issuer | Unknown |
| Valid From | Unknown |
| Valid To | Unknown |
| Days Remaining | Unknown |
| HSTS | Unknown |
| Certificate Notes |
Security Headers
| Header | Present | Value | Assessment |
|---|
Reputation Sources
| Source | Type | Result | Last Update |
|---|---|---|---|
| Registration Records Review | Domain | Registration record profile retrieved. | 2026-09-15 16:25:17 |
| DNS / Infrastructure | Infrastructure | DNS records collected. | 2026-09-15 16:25:17 |
| SSL / TLS | Security | SSL connection could not be established: | 2026-09-15 16:25:17 |
| Network Context Review | Infrastructure | Hosting context was retrieved successfully. | 2026-09-15 16:25:17 |
| Malware Delivery Review | Reputation | No malware delivery host match was found. | 2026-09-15 16:25:17 |
| Detection Intelligence | Reputation | Our detection review found 0 malicious and 1 suspicious engine verdicts. | 2026-09-15 16:25:19 |
| Browser Safety Review | Reputation | No unsafe browsing match was found. | 2026-09-15 16:25:19 |
| Network Reputation Review | Reputation | No strong network abuse indication was found: score 22 with 24 reports. | 2026-09-15 16:25:19 |
| Threat Context Review | Reputation | No additional threat context was found. | 2026-09-15 16:25:20 |
Network Reputation Analysis
| Source Summary | No strong network abuse indication was found: score 22 with 24 reports. |
|---|---|
| IP Address | 3.33.130.190 |
| Public IP | Yes |
| IP Version | 4 |
| Whitelisted | No |
| Abuse Confidence Score | 22 |
| Country | United States of America (US) |
| Usage Type | Content Delivery Network |
| ISP | Amazon Technologies Inc. |
| Associated Domain | amazon.com |
| Hostnames | a2aa9ff50de748dbe.awsglobalaccelerator.com |
| Tor Exit Node | No |
| Total Reports | 24 |
| Distinct Reporting Users | 8 |
| Last Reported At | 2026-09-08T22:59:32+00:00 |
Recent Abuse Reports
These recent report rows help explain why this network address has been reported.
| Reported At | Categories | Comment | Reporter ID | Reporter Country |
|---|---|---|---|---|
| 2026-09-08T20:28:00+00:00 | 17, 10, 11, 7 | schoolreachlab.com | 26956 | United States of America (US) |
| 2026-08-20T13:44:00+00:00 | 10, 11, 17, 7 | infomtric.info | 26956 | United States of America (US) |
| 2026-08-18T11:04:15+00:00 | 14 | Blocked by UFW (TCP on 47954) Source port: 80 TTL: 250 Packet length: 40 TOS: 0x00 This report (for 3.33.130.190) was generated by: https://github.com/sefinek/UFW-AbuseIPDB-Reporter | 209271 | United States of America (US) |
| 2026-08-07T19:48:00+00:00 | 17, 7 | Dear Team, We kindly request the review and reclassification of the IP 3.33.130.190 as malicious, as it is being used in phishing activities that impersonate our registered trademark LEGENDARY VACATION CLUB. This IP is not official nor authorised by our organisation and is being used to deceive users by impersonating our brand, posing a potential risk to the public and affecting the reputation of the organisation. We would appreciate your assistance in reviewing and updating the classification of this domain within your security databases. Best regards, Indra Sistemas México S.A. de C.V. ciberinteligencia@indracompany.com | 296116 | Mexico (MX) |
| 2026-08-06T15:41:24+00:00 | 7, 21 | Phishing site on 3.33.130.190. URL: https://pusulabetgirisi.org Brand: pusulabet | 302902 | Netherlands (NL) |
| 2026-08-06T00:16:55+00:00 | 7, 21 | Phishing site on 3.33.130.190. URL: https://pusulabetgirisi.org | 302902 | Netherlands (NL) |
| 2026-08-04T00:28:00+00:00 | 17, 7 | Dear Team, We kindly request the review and reclassification of the IP maillegendaryvacationclub.com as malicious, as it is being used in phishing activities that impersonate our registered trademark LEGENDARY VACATION CLUB. This ip is not official nor authorised by our organisation and is being used to deceive users by impersonating our brand, posing a potential risk to the public and affecting the reputation of the organisation. We would appreciate your assistance in reviewing and updating the classification of this domain within your security databases. Best regards, Indra Sistemas México S.A. de C.V. ciberinteligencia@indracompany.com | 296116 | Mexico (MX) |
| 2026-08-02T23:15:51+00:00 | 7, 21 | Phishing site on 3.33.130.190. URL: https://pusulabetgirisi.org | 302902 | Netherlands (NL) |
| 2026-08-01T22:32:38+00:00 | 7, 21 | Phishing site on 3.33.130.190. URL: https://pusulabetgirisi.org | 302902 | Netherlands (NL) |
| 2026-07-29T22:25:03+00:00 | 7, 21 | Phishing site on 3.33.130.190. URL: https://pusulabetgirisi.org | 302902 | Netherlands (NL) |
| 2026-07-28T21:56:47+00:00 | 7, 21 | Phishing site on 3.33.130.190. URL: https://pusulabetgirisi.org | 302902 | Netherlands (NL) |
| 2026-07-27T21:24:16+00:00 | 7, 21 | Phishing site on 3.33.130.190. URL: https://pusulabetgirisi.org | 302902 | Netherlands (NL) |
| 2026-07-25T18:39:35+00:00 | 7, 21 | Phishing site on 3.33.130.190. URL: https://pusulabetgirisi.org | 302902 | Netherlands (NL) |
| 2026-07-25T12:56:09+00:00 | 3, 7 | Pig Butchering Scam Domain Report This domain is suspected of being part of a "Pig Butchering" scam — a form of cyber-enabled investment fraud involving manipulation, deception, and large-scale financial exploitation, often through fake cryptocurrency platforms. The case is submitted for review and enforcement action by relevant U.S. authorities and partners, including but not limited to: FBI, USSS, CCIPS, UNODC, DOJ, FTC, SEC, CFTC, FinCEN, IRS-CI, DHS, HSI, ICE, USDT, USPIS, NCIJTF, CISA, IC3, OCC, OFAC, FDIC, FINRA, CFPB, USMS, DS, NSA, CIA, DEA, DC3, USAO, NW3C, MS-ISAC, and APWG. We request that all relevant technical, financial, and operational data tied to this domain be reviewed and investigated under the appropriate statutes and interagency cooperation frameworks. | 206024 | United States of America (US) |
| 2026-07-23T10:30:35+00:00 | 7, 21 | Phishing site on 3.33.130.190. URL: https://pusulabetgirisi.org | 302902 | Netherlands (NL) |
| 2026-07-18T09:34:05+00:00 | 18, 22 | Banned by fail2ban: blossomd | 329366 | United States of America (US) |
| 2026-07-17T20:25:23+00:00 | 7, 21 | Phishing site on 3.33.130.190. URL: https://mrking.org Brand: meritking | 302902 | Netherlands (NL) |
| 2026-07-16T14:39:00+00:00 | 10, 11, 17, 7 | growthmatrixlabs.com | 26956 | United States of America (US) |
| 2026-07-15T20:27:07+00:00 | 7, 21 | Phishing site on 3.33.130.190. URL: https://mrking.org/ Brand: meritking | 302902 | Netherlands (NL) |
| 2026-07-10T23:55:00+00:00 | 2, 9, 14, 17, 20, 21, 22, 23, 7, 13, 16 | This is a malicious IP Address | 300911 | United States of America (US) |
| 2026-07-08T11:12:00+00:00 | 10, 11, 17, 7 | infomtric.info | 26956 | United States of America (US) |
| 2026-07-02T02:40:46+00:00 | 14 | Blocked by UFW (TCP on 46568) Source port: 443 TTL: 248 Packet length: 40 TOS: 0x00 This report (for 3.33.130.190) was generated by: https://github.com/sefinek/UFW-AbuseIPDB-Reporter | 209271 | United States of America (US) |
| 2026-06-25T18:09:00+00:00 | 11, 7 | BS LinkedIn profile optimisation spam | 73571 | Germany (DE) |
| 2026-06-23T13:58:00+00:00 | 10, 11, 17, 7 | infomtric.info | 26956 | United States of America (US) |
Detection Analysis
| Source Summary | Our detection review found 0 malicious and 1 suspicious engine verdicts. |
|---|---|
| Malicious Engines | 0 |
| Suspicious Engines | 1 |
| Harmless Engines | 55 |
| Undetected Engines | 33 |
| Timeout Engines | 0 |
Flagging Engines
These review engines marked the domain during the latest detection review.
| Engine | Category | Result | Method |
|---|---|---|---|
| Gridinsoft | Suspicious | spam | blacklist |
Related Resolutions
Our review captured 4 historical resolution records for this domain. The most recent rows are shown below.
| Date | Host | Resolver | IP | Host Detections | IP Detections |
|---|---|---|---|---|---|
| 2025-06-03 | ppwpn.com | VirusTotal | 3.33.130.190 | 1 / 89 | 4 / 89 |
| 2023-10-24 | ppwpn.com | VirusTotal | 15.197.148.33 | 1 / 89 | 5 / 89 |
| 2019-08-16 | ppwpn.com | VirusTotal | 23.229.165.67 | 1 / 89 | 0 / 89 |
| 2015-11-10 | ppwpn.com | VirusTotal | 69.172.201.208 | 1 / 89 | 1 / 89 |
Related Subdomains
Our review captured 3 related subdomains. The first rows are shown below.
| Subdomain | Detections | Recent DNS Values |
|---|---|---|
| ppwpn.com | 1 / 89 | ns31.domaincontrol.com, 3.33.130.190, 15.197.148.33 |
| www.ppwpn.com | 1 / 89 | ppwpn.com, ns32.domaincontrol.com, ns31.domaincontrol.com |
| digital.ppwpn.com | 0 / 89 | 2600:9000:2162:aa00:1f:3e38:ba80:93a1, d3gu3ka5b5dvqi.cloudfront.net, 2600:9000:2162:c800:1f:3e38:ba80:93a1 |
Historical Registration Changes
Our review captured 5 historical registration records. The first rows are shown below.
| First Seen | Last Updated | Registrar | Creation Date | Expiry Date |
|---|---|---|---|---|
| 2026-05-19 | 2026-05-07 | GoDaddy.com, LLC | 2019-08-13T21:47:25Z | 2027-08-13T21:47:25Z |
| 2025-10-04 | 2025-08-14 | GoDaddy.com, LLC | 2019-08-13T21:47:25Z | 2026-08-13T21:47:25Z |
| 2025-06-07 | 2024-08-14 | GoDaddy.com, LLC | 2019-08-13T21:47:25Z | 2025-08-13T21:47:25Z |
| 2023-10-24 | 2023-08-18 | GoDaddy.com, LLC | 2019-08-13T21:47:25Z | 2024-08-13T21:47:25Z |
| 2019-08-14 | 2019-08-13 | GoDaddy.com, LLC | 2019-08-13T21:47:25Z | 2020-08-13T21:47:25Z |
Risk Signals
| Signal | Severity | Description | Impact |
|---|---|---|---|
| Detection engine hits | High | Multiple engines flag this domain as suspicious or malicious. | 26 |
| No valid HTTPS certificate | High | The site does not present a valid SSL/TLS certificate. | 22 |
Positive Signals
| Signal | Severity | Description | Impact |
|---|---|---|---|
| Older domain | Medium | The domain has existed for a longer period of time. | 10 |
| No unsafe browsing hit | Medium | The reviewed URL was not found in the checked browser safety data. | 8 |
| No malware host hit | Low | No public malware delivery match was found for this host. | 4 |
Technical Scam Indicators
| HTTP Status | Unknown |
|---|---|
| Final URL | Unknown |
| Redirects | 0 |
| Title | Unknown |
| Meta Description | Unknown |
| Canonical | Unknown |
| Server | Unknown |
| X-Powered-By | Unknown |
| CMS Hints | Unknown |
| Suspicious Keywords | None |
| Indexability | Unknown |
Remove Ppwpn.com
First, you must know which browser you are using.
Since these notifications originate from the browser settings, you must remove the unwanted notifications from your internet browser.
Below you will find the removal steps listed by browser.
Choose the browser you use and follow the instructions. Are you unsure? Then follow all instructions and check every installed browser.
Microsoft Edge
First open the Microsoft Edge browser.
Then click on the menu icon at the top right.
Then click on Settings.
On the left side in the menu click on Privacy, search and services.
If you do not see this menu, enlarge the Microsoft Edge window.
Click on Site permissions to open the website settings.
Now click again on All permissions.
Since these are unwanted notifications, click on Notifications.
Here you see all websites that are allowed to send notifications.
In the settings for Customized behaviors click on the three horizontal dots to the right of the URL.
Confirm by clicking on Remove.
You have now disabled the unwanted pop-ups from Ppwpn.com in the Microsoft Edge browser.
Google Chrome
To remove the unwanted notifications from Ppwpn.com in Google Chrome, follow the steps below.
First open the Google Chrome browser.
Then click on the menu icon at the top right.
Click on Settings in the menu.
On the left side in the menu click on Privacy and security.
Then click on Site settings.
To remove the unwanted notifications, click on Notifications.
In the settings for Customized behaviors, click below at Allowed to send notifications, to the right of the URL on the three horizontal dots, and then on Remove.
You have now removed the unwanted pop-ups and notifications from Ppwpn.com in the Google Chrome browser.
Run a Malwarebytes scan to remove malware and protect your device
Removing malicious notifications originating from a fraudulent or dangerous website is an important first step. To ensure that your device also remains free of other potential threats, you can perform a full scan with Malwarebytes. Follow the steps below to correctly install Malwarebytes, run a scan, and safely remove detected threats.
Download and install Malwarebytes
- Go to the official website of Malwarebytes to download the free version and the installer (click here).
- Select the option that best suits your needs (there is a free version and a Premium version with additional features).
- After downloading, open the installation file to start the installation. Follow the steps in the installation wizard to install Malwarebytes on your device.
Run the first Malwarebytes scan
- Once the installation is complete, open Malwarebytes.
- Before starting the scan, update Malwarebytes to the latest malware database.
- Click on Scan in the main menu. Select a full scan to thoroughly check your entire device.
Review and remove detected threats
- After the scan, Malwarebytes will display a list of all detected threats.
- Review the results and choose Quarantine or Remove for each threat.
- After the removal is completed, it is often recommended to restart your device.
Additional protection with Malwarebytes
Malwarebytes offers a Premium version with additional features such as real-time protection and scheduled scans. Consider this version if you want to prevent unwanted notifications, malicious websites, or malware from appearing again. By using these comprehensive scanning and security options from Malwarebytes, you not only protect your device from dangerous websites but also ensure that any hidden malware and other potential threats are detected and removed.
I hope these steps help you remove malicious content and threats from your system. With these steps, you can successfully clean your system. Do you still have questions? Feel free to leave a comment! Thank you for reading.
I hope I was able to help you with this. If this guide helped you, please share it with others.
Thanks for reading!