maga-zine-luiza.com
“Loja — Magalu”
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is domainabuse@tucows.com.
The latest stored availability evidence still shows the domain reachable; 7 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
maga-zine-luiza.com — 마지막으로 알려진 활성 (HTTP 200). 브랜드 사칭: Magalu; 사기 유형: Impersonation. 증거 요약: VirusTotal 14/89 (alphaMountain.ai, BitDefender, CRDF, ESET, Forcepoint ThreatSeeker); URLQuery 6 alerts; URLScan malicious verdict; Spamhaus DBL_SPAM; CF Radar malicious; PhishDestroy score 100/100. 등록기관: TUCOWS.COM, CO.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
증거 요약
PhishDestroy first observed maga-zine-luiza.com on Sep 13, 2026. Stored content metadata identifies Magalu as the apparent target. The captured page title is “Loja — Magalu”. Page analysis recorded additional brand references to Base and Google. Stored page analysis classifies the content as impersonation. Current evidence score: 100/100 (critical).
Positive findings are stored from 5 sources: VirusTotal, Spamhaus DBL, Cloudflare Radar, URLQuery, and URLScan. VirusTotal recorded 14 detections among 89 engines: alphaMountain.ai, BitDefender, CRDF, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Kaspersky, Lionic, Seclookup, SOCRadar, Sophos, VIPRE on Sep 15, 2026 at 02:03 UTC. Spamhaus DBL: DBL_SPAM on Sep 13, 2026 at 14:30 UTC. Cloudflare Radar classified the hostname as malicious and placed it in the phishing category; its verdict timestamp was not retained. URLQuery recorded 6 threat-system alerts on Sep 13, 2026 at 12:42 UTC. URLScan returned a malicious verdict with score 100; scan metadata linked the capture to Magalu and assigned phishing as its category on Sep 15, 2026 at 03:30 UTC. Non-positive and contextual checks: AlienVault OTX listed 4 community pulse references (not vendor detections) on Sep 13, 2026 at 13:13 UTC. The separate external-blocklist snapshot contained no matches on Sep 20, 2026 at 10:20 UTC. Google Safe Browsing returned no flag on Sep 19, 2026 at 16:01 UTC.
HTTP 200 was recorded on Sep 20, 2026 at 10:42 UTC. Registration records for the domain list TUCOWS.COM, CO. as the registrar and Sep 10, 2026 as the creation date. Registration preceded first observation by 2 days. At collection time, the hostname resolved to 188.114.96.3 on AS13335 (Cloudflare, Inc.). The IP and ASN identify shared Cloudflare edge infrastructure; the origin server is not established by this address. DOM analysis on Sep 13, 2026 at 14:20 UTC returned 100/100. The evidence archive retains 3 visual captures from PhishDestroy, URLScan, and URLQuery. TLS metadata lists Let's Encrypt / YE2 as the certificate issuer with validity through Dec 9, 2026; checked Sep 13, 2026 at 13:02 UTC.
The content indicators and 5 positive source findings support the current Magalu-themed impersonation classification.
네트워크 보안 인텔리전스
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | site-ma-ga-zine-luiza.com |
malicious | Sinkholed |
| DNS4EU | site-ma-ga-zine-luiza.com |
malicious | Sinkholed |
| OpenDNS | maga-zine-luiza.com |
phishing | Phishing Block |
| CIRA Canadian Shield DNS | maga-zine-luiza.com |
malicious | Sinkholed |
| Cloudflare DNS | maga-zine-luiza.com |
malicious | Sinkholed |
| DigiCert UltraDNS | maga-zine-luiza.com |
malicious | Sinkholed |
Forensic History & Detection Timeline
-
VirusTotal Detections Update Sep 13, 2026 · 15:11 UTCVirusTotal scanner detections updated from 0 to 1. Added scanner alerts: OpenPhish.
-
Threat First Observed Sep 13, 2026 · 14:38 UTCDomain ingestion complete. Initial state is marked as alive pointing to IP
188.114.96.3.
위협 대응 Pipeline
공개 차단 목록 상태
Evasion analysis
Cloaking suspected: scanner and victim titles differ
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not yet scanned
- Last cloaking scan
- Server header seen by scanner
cloudflare
Scanner note: alive_content: raw=ok; http=200; via=https_proxy; server=cloudflare
기술 · 5 identified
VirusTotal 분석
증거 및 외부 보고서
PD-20260913-1FF071 Recipient: domainabuse@tucows.com Abuse notice text as sent to the provider
Registrar: Tucows Domains Inc (Canada) Policy Violations: Participates in DNS Abuse Framework; explicitly recognizes phishing, malware, botnets, pharming, spam-as-vector as abuse requiring registrar action Applicable Laws: Criminal Code §342.1 (unauthorized access), §380 (fraud)
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.