VirusTotal
5 / 91
“anjar.shop”
anjar.shop appears in a PhishDestroy internal listing and drew 5 detections across 91 VirusTotal scanners on 2026-10-02, the same date as the OTX check. The domain was first observed on 2026-10-02, so the recorded window is narrow.
The VirusTotal record for anjar.shop, checked 2026-10-02, reports 5 detections out of 91 scanners. OTX, checked 2026-10-02, shows 1 pulse, and the PhishDestroy internal listing is recorded as true. The registrar is Dynadot Inc., with registration dated 2026-06-02, and the resolved IP is 193.162.133.154.
The VirusTotal and OTX figures describe different source measurements, so they should be read separately rather than merged into a single score. Because first observation, the VirusTotal check, and the OTX check all fall on 2026-10-02, the records offer a snapshot rather than a sequence of change. The registration date of 2026-06-02 is earlier than that snapshot, but it does not by itself explain the detections or the pulse.
For anjar.shop, preserve the PhishDestroy listing entry, the OTX pulse record, and the VirusTotal scan result as separate source records. Compare the VirusTotal detection count and scanner total against later scans, and compare the OTX pulse count against later OTX checks, keeping each source distinct. Recheck the PhishDestroy listing to see whether it remains present.
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
Scanner note: transient_502: raw=transient_502; http=502; via=http_proxy
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
jessica.ns.cloudflare.comLocation describes the IP network.
Saved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
193.162.133.154. 9 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Select your country to get official cybercrime contacts, or create a complaint draft →.
Template-based draft · optional AI wording assistance requires separate consent
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowSubmit suspicious domains to our threat database — protect the community
ReportRecent phishing reports and observed availability changes
MonitorMonitor live threats or contest this listing if you believe it's a false positive