shop1300.biz is currently active and classified as a high‑risk generic phishing site. The domain resolves to the IPv4 address 91.206.71.135 and is served through Cloudflare’s name servers cody.ns.cloudflare.com and jamie.ns.cloudflare.com. VirusTotal records indicate that one of ninety‑one scanning engines has flagged the domain, demonstrating limited but non‑zero detection across the security community. The domain appears on a single security blocklist and has been explicitly blocked by the PhishDestroy mitigation service.
Its presence on a single blocklist indicates early‑stage detection, and the solitary vendor flag suggests that broader awareness may still be developing. No additional intelligence such as page title, SSL certificate details, or observed brand impersonation has been published, leaving the exact content and intended victim profile unverified. The high risk rating reflects the potential for credential theft or financial loss typical of generic phishing campaigns. The lack of further public indicators suggests that the infrastructure is modest, relying on Cloudflare’s DNS and a single hosting IP, which may simplify takedown actions if the hosting provider cooperates.
Defenders should add 91.206.71.135 to network‑level deny lists, enforce DNS filtering for shop1300.biz, and monitor for any future changes in detection counts or blocklist appearances. Continuous observation of VirusTotal and other threat‑intelligence feeds is recommended to capture emerging evidence that could clarify the phishing payload or targeted brand. Until more detailed payload analysis is available, the domain should be treated as malicious and blocked across enterprise perimeter defenses.