Analysis of the domain jerseypurchase.com shows that it was registered on July 22 2026 through Fewmoretaps OU d/b/a Trustname.com and is hosted on Cloudflare infrastructure, using the authoritative nameservers mario.ns.cloudflare.com and tessa.ns.cloudflare.com. DNS resolution points to the IPv4 address 188.114.97.3. The domain is currently listed as active and has been blocked by the PhishDestroy feed, indicating that at least one security‑intelligence source has observed malicious use. A VirusTotal scan performed by 91 antivirus and URL‑reputation engines returned no detections, but the absence of alerts does not constitute evidence of benign behavior.
The domain also appears on a single external blocklist, confirming that it has been flagged by at least one additional reputation service. The available data do not include HTTP response codes, SSL certificate details, page title, or any observed payload, so the exact phishing landing page content remains unknown. The lack of public indicators such as a known brand in the page title or a disclosed scam kit limits attribution beyond the classification of “banking phishing” supplied in the incident brief.
Defenders should therefore treat any traffic to jerseypurchase.com as potentially malicious. Recommended mitigations include adding the domain to local deny lists, updating web‑proxy and DNS filtering policies to block resolution to 188.114.97.3, and monitoring for any future detections in additional threat‑intel feeds. Continuous re‑evaluation is advised, as the domain’s short age (registered only eight days prior to the report date) suggests that its operational profile may evolve rapidly.