Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@bluehost.com.
The latest stored availability evidence still shows the domain reachable; 27 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
balconyresidences[.]com[.]br
“Not Acceptable!”
balconyresidences.com.br is currently active and hosts a generic phishing infrastructure as indicated by multiple intelligence sources. The domain was registered on 11 April 2023 and uses the authoritative name servers ns254.prodns.com.br and ns255.prodns.com.br. DNS resolution points to the IPv4 address 162.241.203.20, which remains reachable as of the report date. VirusTotal has recorded 14 detections out of 91 scanning engines, confirming that the domain is flagged by security vendors. AlienVault OTX lists the domain in a single threat‑intel pulse, further corroborating its malicious use. No public web content analysis is available, so the exact phishing lures, credential‑stealing pages, or targeted brands cannot be confirmed at this time. The limited attribution suggests a small‑scale operation, but the high risk rating reflects the potential for credential harvesting. Defenders should block both the domain and its resolving IP at perimeter defenses, monitor DNS queries for the associated name servers, and incorporate the indicator into threat‑intel feeds. Continuous re‑evaluation is advised to detect any changes in hosting or payload.
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | balconyresidences.com.br |
malicious | Sinkholed |
| Cloudflare DNS | balconyresidences.com.br |
malicious | Sinkholed |
| Hagezi Threat Feed | balconyresidences.com.br |
malicious | Sinkholed |
| Quad9 DNS | balconyresidences.com.br |
malicious | Sinkholed |
Threat Response Pipeline
Public Blocklist Status
Technologies · 9 identified
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. Features include a plugin architecture and a template system.
wordpress.org 100% confidenceApache is a free and open-source cross-platform web server software.
httpd.apache.org 100% confidenceSwiper is a JavaScript library that creates modern touch sliders with hardware-accelerated transitions.
swiperjs.com 100% confidenceSlider Revolution is a flexible and highly customisable slider.
www.sliderrevolution.com 100% confidenceLightbox is small javascript library used to overlay images on top of the current page.
lokeshdhakar.com 100% confidenceQuery Migrate is a javascript library that allows you to preserve the compatibility of your jQuery code developed for versions of jQuery older than 1.9.
github.com 100% confidencejQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 100% confidenceVirusTotal Analysis
Evidence & External Reports
PD-20260717-9AD824 Recipient: abuse@bluehost.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive