reddefend.shop
Appeared in the .shop zone on Tuesday, September 15, 2026; by the end of that day the census found active website. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
The page is a self-branded 'Resto' restaurant POS back-office login that openly publishes demo credentials (owner@resto.test / password 'password', till PINs), which is the shape of a developer demo or SaaS staging instance, not a credential-capture lure; no third-party brand, logo or product language is impersonated.
The domain reddefend.shop hosts a login page impersonating Resto (a restaurant management system), displaying the Resto logo and branding, with a credential capture form (email + password) that posts to itself over HTTP. The page includes demo account credentials and uses a deceptive domain name unrelated to the legitimate Resto brand, matching the sealed-room phishing pattern: credential form with no offsite links, posting to self, designed to harvest login credentials.
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Tuesday, September 15, 2026

Same data as JSON: /api/zone/domain/reddefend.shop. This page is not indexed by search engines and does not link to the site it describes.