VirusTotal
15 / 91
PhishDestroy first observed apth.shop on Oct 3, 2026. Current evidence score: 95/100 (critical).
Positive findings are stored from 2 sources: VirusTotal and URLQuery. VirusTotal recorded 15 detections among 91 engines: alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Kaspersky, Lionic, Netcraft, Sophos, VIPRE, Webroot on Oct 3, 2026 at 08:04 UTC. URLQuery recorded 2 detections; no observation timestamp was retained. Additional recorded evidence: AlienVault OTX listed 3 community pulse references (not vendor detections) on Oct 3, 2026 at 08:04 UTC. URLScan captured the page on Oct 3, 2026 at 07:35 UTC.
The collector marked the hostname reachable on Oct 3, 2026 at 07:35 UTC, but did not retain the HTTP response code. Latest classified outcome: unknown; cause stale current evidence on Oct 3, 2026 at 05:33 UTC. At collection time, the hostname resolved to 193.162.133.218 on AS199242 (malakmadze Malakmadze Web LLC, GE). The evidence archive retains 3 visual captures from PhishDestroy and URLScan; the captures preserve the landing-page appearance.
The record contains 2 positive source findings supporting the current phishing classification.
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
arely.ns.cloudflare.comjoel.ns.cloudflare.comLocation describes the IP network.
Google PageSpeed Insights — mobile performance audit of apth.shop · checked Oct 3, 2026
193.162.133.218. 7 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Select your country to get official cybercrime contacts, or create a complaint draft →.
Template-based draft · optional AI wording assistance requires separate consent
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowSubmit suspicious domains to our threat database — protect the community
ReportRecent phishing reports and observed availability changes
MonitorMonitor live threats or contest this listing if you believe it's a false positive