Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is net-abuse@hostpapa.com.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
christinavansluys[.]ca
“Christina van Sluys – Calgary Realtor – Relationships built on Trust, Service & Results!”
christinavansluys.ca — Não verificado. Tipo de golpe: Generic Phishing. Resumo das evidências: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); PhishDestroy score 89/100. Registrador: Go Daddy Domains Canada.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of the domain christinavansluys.ca reveals an active phishing site impersonating a Calgary real estate professional. The domain was registered on February 21, 2026, through Go Daddy Domains Canada, Inc., and currently resolves to IP address 66.102.128.189, hosted on AS40092 (HostPapa) in Canada. The site returns an HTTP 200 status, indicating a live webpage, and uses a Let's Encrypt SSL certificate (R12) for HTTPS encryption. Detected technologies include WordPress, MySQL, PHP, Nginx, and jQuery, suggesting a content management system commonly exploited for phishing due to its plugin vulnerabilities. The page title, 'Christina van Sluys – Calgary Realtor – Relationships built on Trust, Service & Results!', directly mimics a legitimate real estate professional's branding, a tactic often employed to deceive visitors into submitting personal or financial information.
While the exact content of the site remains unanalyzed, the combination of a spoofed professional identity, active hosting infrastructure, and low detection coverage raises concerns. As of July 25, 2026, two of ninety-three security vendors on VirusTotal flag the domain, and it appears on one security blocklist, specifically PhishDestroy. Gridinsoft assigns a trust score of 0/100, further indicating malicious intent. Defenders should note that the domain's nameservers (ns71.domaincontrol.com and ns72.domaincontrol.com) are associated with a registrar frequently used in phishing campaigns.
The use of Let's Encrypt certificates is not inherently suspicious, as they are widely adopted for legitimate and malicious sites alike, but their presence here does not mitigate the risk. Given the current detection rate and blocklist status, organizations are advised to proactively block this domain at the network level and monitor for related infrastructure. Additional scrutiny of domains registered through the same registrar or resolving to the same IP range may uncover further malicious activity.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 5 identified
Open-source CMS powering over 40% of websites worldwide.
Open-source relational database management system.
Server-side scripting language designed for web development.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Análise do VirusTotal
Evidências arquivadas
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of christinavansluys.ca · checked Mar 2, 2026
Evidências e relatórios externos
PD-20260219-E044BA Recipient: net-abuse@hostpapa.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo