Criticalscore 60 · flagged Tuesday, September 1, 2026

garde-maiade.shop

Appeared in the .shop zone on Tuesday, September 1, 2026; by the end of that day the census found active website about e-commerce & retail. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

page impersonates a brand
matched: FedEx
+22
brand in page title, not in the name
matched: nationwide
+20
form on a brand-styled page
matched: has_form
+18
Registrar
GNAME.COM PTE. LTD.
Nameserver provider
Nameservers
gene.ns.cloudflare.com, louis.ns.cloudflare.com
First-day state
active website
HTTP status
200
Page title
High-quality medical uniforms, specially designed for healthcare workers | Garde-Malade-dr – Autumn Special Offer – Free Shipping Nationwide – Lightning Deliver
Has a form
yes
Brand echoed

Model opinions

Second opinionlooks like a scamtarget: Garde-Malade (garde-malade-dr.it.com)confidence 79%· claude-opus-5

The domain is a homoglyph typosquat (l→i) of the real store garde-malade-dr.it.com, and a leaked PHP open_basedir warning shows the WordPress/WooCommerce site was cloned wholesale from that original path; placeholder 'Lorem ipsum' product blocks and aggressive '70% off / free FedEx shipping' banners indicate a cloned fake shop set up to take checkout payments rather than a legitimate merchant. The FedEx and 'nationwide' mentions are ordinary shipping copy, not brand impersonation.

First passlooks like phishingtarget: FedExconfidence 85%· claude-haiku-4-5

The page prominently impersonates FedEx shipping claims ('Free FedEx shipping on every U.S. order') to build trust, while the domain 'garde-maiade.shop' and page title reference 'Garde-Malade' medical uniforms—a classic bait-and-switch phishing technique. The presence of a login form posting to itself with no offsite links, combined with the sealed-room infrastructure and the false FedEx branding used as a lure, indicates credential capture intent.

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Tuesday, September 1, 2026

Screenshot of garde-maiade.shop taken by the zone census on 2026-09-01

Same data as JSON: /api/zone/domain/garde-maiade.shop. This page is not indexed by search engines and does not link to the site it describes.