maga-zine-luiza.com
“Loja — Magalu”
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is domainabuse@tucows.com.
The latest stored availability evidence still shows the domain reachable; 7 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
maga-zine-luiza.com — Ultimo attivo conosciuto (HTTP 200). Simulazione del marchio: Magalu; Tipo di truffa: Impersonation. Riepilogo delle prove: VirusTotal 14/89 (alphaMountain.ai, BitDefender, CRDF, ESET, Forcepoint ThreatSeeker); URLQuery 6 alerts; URLScan malicious verdict; Spamhaus DBL_SPAM; CF Radar malicious; PhishDestroy score 100/100. Registrar: TUCOWS.COM, CO.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Riepilogo delle prove
PhishDestroy first observed maga-zine-luiza.com on Sep 13, 2026. Stored content metadata identifies Magalu as the apparent target. The captured page title is “Loja — Magalu”. Page analysis recorded additional brand references to Base and Google. Stored page analysis classifies the content as impersonation. Current evidence score: 100/100 (critical).
Positive findings are stored from 5 sources: VirusTotal, Spamhaus DBL, Cloudflare Radar, URLQuery, and URLScan. VirusTotal recorded 14 detections among 89 engines: alphaMountain.ai, BitDefender, CRDF, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Kaspersky, Lionic, Seclookup, SOCRadar, Sophos, VIPRE on Sep 15, 2026 at 02:03 UTC. Spamhaus DBL: DBL_SPAM on Sep 13, 2026 at 14:30 UTC. Cloudflare Radar classified the hostname as malicious and placed it in the phishing category; its verdict timestamp was not retained. URLQuery recorded 6 threat-system alerts on Sep 13, 2026 at 12:42 UTC. URLScan returned a malicious verdict with score 100; scan metadata linked the capture to Magalu and assigned phishing as its category on Sep 15, 2026 at 03:30 UTC. Non-positive and contextual checks: AlienVault OTX listed 4 community pulse references (not vendor detections) on Sep 13, 2026 at 13:13 UTC. The separate external-blocklist snapshot contained no matches on Sep 20, 2026 at 10:20 UTC. Google Safe Browsing returned no flag on Sep 19, 2026 at 16:01 UTC.
HTTP 200 was recorded on Sep 20, 2026 at 10:42 UTC. Registration records for the domain list TUCOWS.COM, CO. as the registrar and Sep 10, 2026 as the creation date. Registration preceded first observation by 2 days. At collection time, the hostname resolved to 188.114.96.3 on AS13335 (Cloudflare, Inc.). The IP and ASN identify shared Cloudflare edge infrastructure; the origin server is not established by this address. DOM analysis on Sep 13, 2026 at 14:20 UTC returned 100/100. The evidence archive retains 3 visual captures from PhishDestroy, URLScan, and URLQuery. TLS metadata lists Let's Encrypt / YE2 as the certificate issuer with validity through Dec 9, 2026; checked Sep 13, 2026 at 13:02 UTC.
The content indicators and 5 positive source findings support the current Magalu-themed impersonation classification.
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | site-ma-ga-zine-luiza.com |
malicious | Sinkholed |
| DNS4EU | site-ma-ga-zine-luiza.com |
malicious | Sinkholed |
| OpenDNS | maga-zine-luiza.com |
phishing | Phishing Block |
| CIRA Canadian Shield DNS | maga-zine-luiza.com |
malicious | Sinkholed |
| Cloudflare DNS | maga-zine-luiza.com |
malicious | Sinkholed |
| DigiCert UltraDNS | maga-zine-luiza.com |
malicious | Sinkholed |
Forensic History & Detection Timeline
-
VirusTotal Detections Update Sep 13, 2026 · 15:11 UTCVirusTotal scanner detections updated from 0 to 1. Added scanner alerts: OpenPhish.
-
Threat First Observed Sep 13, 2026 · 14:38 UTCDomain ingestion complete. Initial state is marked as alive pointing to IP
188.114.96.3.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Evasion analysis
Cloaking suspected: scanner and victim titles differ
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not yet scanned
- Last cloaking scan
- Server header seen by scanner
cloudflare
Scanner note: alive_content: raw=ok; http=200; via=https_proxy; server=cloudflare
Tecnologie · 5 identified
Analisi di VirusTotal
Dati e relazioni esterne
PD-20260913-1FF071 Recipient: domainabuse@tucows.com Abuse notice text as sent to the provider
Registrar: Tucows Domains Inc (Canada) Policy Violations: Participates in DNS Abuse Framework; explicitly recognizes phishing, malware, botnets, pharming, spam-as-vector as abuse requiring registrar action Applicable Laws: Criminal Code §342.1 (unauthorized access), §380 (fraud)
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo