static[.]red-hat[.]shop
Phishing and security check for static.red-hat.shop
“Facebook”
static.red-hat.shop is currently listed as an active generic phishing infrastructure. DNS resolution points exclusively to the IPv4 address 52.54.199.95; the authoritative name servers could not be retrieved, indicating either a misconfiguration or deliberate concealment. VirusTotal analysis shows that 14 of 91 security vendors have flagged the domain as malicious, reinforcing the high‑risk assessment. No additional contextual data such as page titles, brand impersonation, or malware kits have been disclosed, so the exact phishing lures employed remain unknown. The observed infrastructure suggests a low‑profile hosting arrangement, potentially leveraging cloud or shared services to minimize attribution. Defenders should immediately block both the domain and its resolved IP at perimeter and endpoint controls, incorporate the indicator into threat‑intel feeds, and monitor for any related DNS or network activity. Continuous re‑evaluation is advised, as further evidence (e.g., payload samples or phishing page screenshots) may emerge that clarifies the campaign’s objectives and target audience.
Threat Response Pipeline
Public Blocklist Status
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive