The domain figural.shop is presently active and has been identified as a credential harvesting operation. Infrastructure analysis shows the domain resolves to the IPv4 address 2.27.4.185 and is hosted on Cloudflare DNS services, with the authoritative name servers joyce.ns.cloudflare.com and rodney.ns.cloudflare.com. VirusTotal records indicate that two of ninety‑one AV and URL scanning engines have flagged the domain, providing limited but notable detection evidence.
The domain appears on a single security blocklist and has been explicitly blocked by the PhishDestroy mitigation service, confirming that external threat‑intel feeds consider it malicious. No public information is available regarding SSL certificate details, HTTP response codes, page title, or any brand or kit attribution, leaving the exact lure and victim‑targeting tactics uncertain.
Defenders should add figural.shop to DNS and URL filtering policies, enforce blocklisting of the associated IP address 2.27.4.185, and monitor for any traffic to the Cloudflare name servers listed. Continuous re‑evaluation is advised, as additional detection signatures or threat‑intel reports may emerge that further clarify the campaign’s scope and payload.