the-residence[.]shop
“The Residence Shop - Official The Residence Merchandise Store”
the-residence.shop — Não verificado. Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 3/91 (alphaMountain.ai, Gridinsoft, SOCRadar); PhishDestroy score 71/100. Registrador: Dynadot.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain the-residence.shop is currently active and has been identified as a credential phishing site. The site returns HTTP status 200 and presents the page title “The Residence Shop - Official The Residence Merchandise Store”. The domain is served through Cloudflare DNS with authoritative nameservers corey.ns.cloudflare.com and jasmine.ns.cloudflare.com, and resolves to the IPv4 address 185.66.143.189. No detections were reported by VirusTotal at the time of analysis (0/95). Infrastructure analysis reveals that the hosting IP belongs to a Cloudflare‑proxied address, which masks the underlying web server and complicates direct attribution. The use of Cloudflare’s DNS and CDN services is common among phishing operators seeking anonymity and resilience. The page title suggests an attempt to appear as an official merchandise store, but the content of the site has not been captured, so the exact phishing vector (e.g., credential capture form) remains unverified. Uncertainties include the lack of observed payload, login forms, or malicious scripts, as the assessment is based solely on passive DNS and HTTP header information. The absence of VirusTotal alerts does not imply safety; many phishing pages evade automated scanners until they are actively visited. Additionally, the IP address may be shared among multiple unrelated sites, so any correlation with other malicious activity must be validated through traffic analysis. Defenders should add the domain to blocklists at the DNS resolver level and monitor outbound connections to 185.66.143.189 for signs of credential‑exfiltration. Logging of HTTP requests to the domain can help confirm whether users are being directed to credential‑harvesting pages. If possible, request a takedown from the hosting provider and continue to track any changes to the DNS records or page title that could indicate a shift in the phishing campaign.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologias · 7 identified
Vue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.
vuejs.org 100% de confiançaGoogle Analytics is a free web analytics service that tracks and reports website traffic.
google.com 100% de confiançaLivewire is a full-stack Laravel framework for building dynamic interfaces.
laravel-livewire.com 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo