Analysis as of July 29, 2026 confirms that tbv24.shop remains active and is currently listed on a single security blocklist. The domain is explicitly blocked by PhishDestroy, indicating that at least one reputable anti‑phishing service has identified it as malicious. DNS resolution points to the IP address 188.114.96.3, which is hosted on Cloudflare infrastructure, as evidenced by the authoritative nameservers joaquin.ns.cloudflare.com and val.ns.cloudflare.com.
The domain was scanned by VirusTotal using 91 independent antivirus and URL scanning engines; none of the vendors reported a detection, but the absence of a flag does not constitute evidence of safety. The presence on a blocklist and the active block by PhishDestroy suggest a higher confidence of malicious intent despite the clean vendor scan. No public page title, SSL certificate details, HTTP response codes, or additional threat intelligence such as OTX or Safe Browsing entries are presently available, leaving the exact content and lure technique of the site unverified.
Defenders should therefore treat tbv24.shop as a high‑risk credential‑harvesting vector: enforce URL filtering to block the domain at the network perimeter, monitor DNS queries for the associated IP and Cloudflare nameservers, and consider adding the domain to internal blocklists. Continuous re‑scanning with multiple vendors is advised to capture any future changes in the payload or hosting configuration.