# PhishDestroy threat dossier — lojaatacadaodastintas.com.br ================================================================ Fetched: 2026-06-25 20:58:16 UTC Canonical: https://phishdestroy.io/domain/lojaatacadaodastintas.com.br/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 82/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain Flagging vendors: Gridinsoft AlienVault OTX: 1 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 2a02:4780:13:1050:0:33f9:5cc:5 (BR, São Paulo) ASN: ASAS47583 AS-HOSTINGER Hostinger International Limited, CY Hosting org: AS47583 Hostinger International Limited Registrar: HSTDOMAINS Nameservers: byte.dns-parking.com, pixel.dns-parking.com Registered: 2026-06-11 Expires: 2029-06-11 Page title: Página padrão ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE1 Expires: 2026-09-09 Status: INVALID chain Fingerprint: 61dbad13433c01de2f84962e4c2e5ef8653fae30ae018afabbfa31acd6882e2f Subject Alternative Names (related infrastructure — often same operator): - www.lojaatacadaodastintas.com.br ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-06-11 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-06-14 13:38:13 UTC (by PhishDestroy tracker) Last verified: 2026-06-25 20:20:35 UTC Neutralised: 2026-06-16 00:38:00 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019ec5ee-6b97-7188-b256-e18a4d7794e0/ Wayback Machine: https://web.archive.org/web/*/lojaatacadaodastintas.com.br crt.sh CT logs: https://crt.sh/?q=%25.lojaatacadaodastintas.com.br Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=lojaatacadaodastintas.com.br AlienVault OTX: https://otx.alienvault.com/indicator/domain/lojaatacadaodastintas.com.br URLhaus: https://urlhaus.abuse.ch/host/lojaatacadaodastintas.com.br/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-18 16:38:21 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy has identified lojaatacadaodastintas.com.br as a generic phishing domain with an elevated risk level, currently offline but still posing a threat to users who may encounter it through cached links or email archives. This domain was likely created to impersonate a paint store or e-commerce site, tricking visitors into submitting sensitive information. The domain was registered through HSTDOMAINS and created on June 11, 2026, resolving to IP address 147.93.39.206. It features a default page titled "Página padrão" and uses a Let's Encrypt SSL certificate (identified as YE1). VirusTotal shows a detection rate of 1 out of 95 security vendors flagging it, while AlienVault OTX includes it in one threat intelligence pulse. Additionally, it appears on one security blocklist, and its trust score is low due to these indicators. Users should avoid interacting with this domain or any links associated with it. If you have already entered credentials or payment information on this site, change your passwords immediately and monitor your financial accounts for suspicious activity. Always verify the legitimacy of e-commerce sites by checking official URLs and using PhishDestroy's verification tools before proceeding with transactions. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: ff3a0706aa6dc4bfaca6f894fa5bdedf TLS cert SHA-256: 61dbad13433c01de2f84962e4c2e5ef8653fae30ae018afabbfa31acd6882e2f ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/lojaatacadaodastintas.com.br/ JSON API: https://api.destroy.tools/v1/check?domain=lojaatacadaodastintas.com.br Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 170,022 domains (14,711 alive under monitoring, 154,619 confirmed takedowns/dead). Site: https://phishdestroy.io