Cloaking on PHISHING website - IP on misused / abused server...

Re: https://threatintelligenceplatform.com/report/replicawatchaaa.com/F7AtFoqIFu (Eset & Fortinet’s flag).
Spamvertizing: http://support.clean-mx.de/clean-mx/portals.php?response=alive&country=BG
Blocklisted on firehol: https://github.com/firehol/blocklist-ipsets/blob/master/hphosts_fsa.ipset
and https://exchange.xforce.ibmcloud.com/ip/78.142.29.77
Zenid click cloaking: https://aw-snap.info/file-viewer/?protocol=not-secure&tgt=replicawatchaaa.com&ref_sel=GSP2&ua_sel=ff&fs=1
and see: http://isithacked.com/check/replicawatchaaa.com%2Fit%2F
also: http://www.domxssscanner.com/scan?url=http%3A%2F%2Freplicawatchaaa.com%2Fit%2F
F-Grade: https://observatory.mozilla.org/analyze.html?host=replicawatchaaa.com
Flagged as with malware: https://urlquery.net/report/ee32e2cb-ff0f-4c12-a346-711687f69fd8
Not considered a scam: https://www.scamadviser.com/check-website/replicawatchaaa.com
Analysis Details:-
Although this website appears to be based in Netherlands there are other countries involved and you should review this information carefully and decide if it is as you expect.
This site is using an anonymous service - which prevents us from identifying the site owner. This can sometimes be just so that the owner does not receive spam, but be aware that many scam sites use this as a method to hide their identify. If this is an ecommerce site - we would suggest you confirm the business address with the website owners. Owner information hidden by the private proxy/guard.

polonus (volunteer website security analyst and website-error hunter)