What Gridinsoft observed on Maisongazon-fr.com
A Gridinsoft threat analyst reviewed the site directly and documented the evidence behind this decision.
GMA-20260815190651-ba76c01a
- Reviewed
- by Gridinsoft Threat Analyst
- Analyst finding
- Phishing
- Evidence basis
- First-party site analysis External vendor intelligence: Context only โ not used for this decision
The independent first-party review confirmed a deceptive clone of an established French merchant. The site reused AG'CO identity details and closely matching catalogue assets, presented internally inconsistent operator disclosures, and collected full customer identity, address, card number, expiry, and CVC through its own checkout endpoint. These combined first-party observations support a high-confidence Phishing verdict. No card data was submitted during the review, and no separate malware file or executable payload was identified.
Analyst findings
Established merchant identity and catalogue were impersonated
The reviewed site reused AG'CO identifiers, telephone details, distinctive product names, and near-identical product images while presenting inconsistent operator details on its own legal page. This is direct evidence of a deceptive merchant clone rather than an independent storefront with a coherent disclosed identity.
Deceptive clone collected full payment-card data
Within the impersonating merchant context, the checkout collected customer identity and postal details together with card number, expiry, and CVC and posted the complete dataset to the site's own endpoint before same-origin verification. This behavior supports a phishing classification focused on payment-card data theft risk.
Domain entered registrar shutdown after live capture
The target was live during the recorded review and became non-resolving shortly afterward, with registry status and nameservers indicating termination. This limits current reachability but does not negate the captured phishing behavior.
Review 6 documented observations View evidence
The storefront returned HTTP 200 and presented the name MaisonGazon while displaying AG'CO business identifiers and contact details, including VAT FR35518331277 and telephone 04 83 16 42 78. Its legal page separately named MaisonGazon SARL, provided only France as the registered-office address, and displayed a different telephone number.
-
HTTP status
200 -
Final URL
https://maisongazon-fr.com/ - Page element TVA FR35518331277
- Page element 04 83 16 42 78
- Public artifact URL https://maisongazon-fr.com/mentions-legales
- File SHA-256 ff44b52edb6c19f7afb9ca616f618492a00a58ab3ce0b7fb57625875cd6b2c66
The established mon-gazon-synthetique.com legal page identifies AG'CO SAS with SIRET 51833127700021, VAT FR35518331277, 435 rue de l'Artisanat in Six-Fours-les-Plages, and telephone 04 83 16 42 78. The reviewed maisongazon-fr.com storefront reused the VAT number and telephone and displayed overlapping AG'CO identity text.
- Public artifact URL https://www.mon-gazon-synthetique.com/content/2-mentions-legales
- Page element AG'CO SAS
- Page element SIRET 51833127700021
- Page element TVA FR35518331277
- Page element 04 83 16 42 78
- File SHA-256 0ce4be2ba3fbc0c86eace9f708c9bc8a1dfa346bc3c2f7fa77c34e5ee8a11633
The reviewed storefront repeated distinctive product names used by the established merchant, including Very Chic / Lyon 35mm, Robusto / Saint-Etienne 38mm, Caresse / Bordeaux 40mm, Savane, and Exotik. Normalized image comparisons for the Very Chic and Robusto product assets produced pixel correlations of 0.997298 and 0.996348 with the corresponding images on mon-gazon-synthetique.com.
- Page element Very Chic / Lyon 35mm
- Page element Robusto / Saint-Etienne 38mm
- Page element Caresse / Bordeaux 40mm
- Analyst observation Normalized image pixel correlation: Very Chic 0.997298; Robusto 0.996348.
- Public artifact URL https://www.mon-gazon-synthetique.com/
The checkout returned HTTP 200 and requested customer email, first name, last name, telephone, postal address, card number, expiry date, and CVC. The active client code serialized those fields and posted them as JSON to the same-origin endpoint /api/payment/checkout, then used a returned job identifier to navigate to /checkout/verify.
-
HTTP status
200 -
Final URL
https://maisongazon-fr.com/checkout - Page element Numรฉro de carte
- Page element Date d'expiration
- Page element CVC
- Analyst observation POST /api/payment/checkout JSON includes customer.email, customer.firstName, customer.lastName, customer.phone, customer.address, card.number, card.expiry, and card.cvv.
- File SHA-256 ac319aacabc67b6e6d60282f1d760e7c3aea319b71fbc338993a22f4121893d4
- File SHA-256 c5544a8842e2f4282149a3a3f8fae44daaf12e8d7b7b788031416e7ae1b9c8b9
The checkout displayed Visa, Mastercard, Amex, CB, Apple Pay, and Google Pay branding and claimed 100 percent secure payment. The active checkout configuration enabled the site's own card form and did not load a client-side tokenization SDK for a named payment processor in the reviewed checkout resources.
- Page element Visa Mastercard Amex CB Apple Pay Google Pay
- Page element Paiement 100% sรฉcurisรฉ
- Analyst observation PAYMENT_OMEGAPAY_ENABLED=true and PAYMENT_NOLIMIT_ENABLED=false in the reviewed client bundle.
- Analyst observation GET /api/payment/checkout returned HTTP 405 and x-matched-path /api/payment/checkout, confirming the same-origin route exists and accepts a different method.
Shortly after the live storefront and checkout were captured, a fresh DNS-based rescan no longer resolved the domain. Registry RDAP showed the domain in redemption period with nameservers FRAUD.EASYDNS.WTF and TERMINATED.EASYDNS.WTF, while the previously resolved Vercel address continued to serve the captured checkout when pinned directly.
- DNS fact Fresh DNS-based scan result: dns_not_resolved.
- DNS fact RDAP status: redemption period.
- DNS fact RDAP nameservers: FRAUD.EASYDNS.WTF and TERMINATED.EASYDNS.WTF.
-
HTTP status
200
Scope and limitations
- No payment-card data was entered or submitted, and the server-side implementation of /api/payment/checkout was not inspected.
- The result applies to the storefront, legal page, checkout, client-delivered code, official-site comparison, DNS, TLS, and registry state reviewed at the recorded time.
- The domain became non-resolving after the live capture; the recorded page and script hashes preserve the reviewed client-side evidence but do not establish how long the content remained reachable afterward.
Help protect others by sharing this page on social media! The more people who know about maisongazon-fr.com, the fewer chances they have to deceive someone else. Help others evaluate maisongazon-fr.com by sharing this page on social media!