VirusTotal
6 / 91
“Aqua-Pure™ Water Systems”
PhishDestroy first observed aquapurefiltersco.shop on Oct 3, 2026. The captured page title is “Aqua-Pure™ Water Systems”. Current evidence score: 88/100 (critical).
Positive findings are stored from 2 sources: VirusTotal and URLQuery. VirusTotal recorded 6 detections among 91 engines: alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, LevelBlue, Netcraft on Oct 3, 2026 at 10:59 UTC. URLQuery recorded 2 detections; no observation timestamp was retained. Additional recorded evidence: AlienVault OTX listed 4 community pulse references (not vendor detections) on Oct 3, 2026 at 10:59 UTC. URLScan captured the page on Oct 3, 2026 at 09:26 UTC.
The collector marked the hostname reachable on Oct 3, 2026 at 09:26 UTC, but did not retain the HTTP response code. Latest classified outcome: unknown; cause probe inconclusive on Oct 3, 2026 at 07:26 UTC. At collection time, the hostname resolved to 46.245.239.106 (AS199242 Malakmadze Web LLC). The recorded endpoint location is Los Angeles, US. DOM analysis on Oct 3, 2026 at 10:20 UTC returned 88/100. The evidence archive retains 2 visual captures from PhishDestroy and URLScan. TLS metadata lists Let's Encrypt / YE2 as the certificate issuer with validity through Dec 22, 2026; checked Oct 3, 2026 at 10:02 UTC.
The content indicators and 2 positive source findings support the current phishing classification.
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
hasslo.ns.cloudflare.commckinley.ns.cloudflare.comLocation describes the IP network.
086195cf7f340f445dedb18bc530082077d515754c29bfda95e5c7723c569b3cSaved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
Google PageSpeed Insights — mobile performance audit of aquapurefiltersco.shop · checked Oct 3, 2026
46.245.239.106. 8 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Select your country to get official cybercrime contacts, or create a complaint draft →.
Template-based draft · optional AI wording assistance requires separate consent
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowSubmit suspicious domains to our threat database — protect the community
ReportRecent phishing reports and observed availability changes
MonitorMonitor live threats or contest this listing if you believe it's a false positive