og6y7c[.]top
“Shopee”
ملخص الأدلة
This domain, og6y7c.top, is flagged for brand impersonation targeting the e-commerce platform Shopee, specifically mimicking backpack product pages. Analysis indicates the domain was designed to deceive users into believing they were interacting with legitimate Shopee listings, likely to harvest credentials, payment details, or distribute malware. No specific drainer kit signatures were identified, but the page title explicitly matched Shopee’s branding, suggesting a focused phishing campaign. Infrastructure analysis reveals the domain resolved to IP 180.178.44.100, hosted on AS45753 (Netsec Limited) in Hong Kong. It was registered via Namemart Limited on April 8, 2025, and achieved a VirusTotal detection score of 18/95 security vendors. The domain appeared on one security blocklist and was blocked by Google Safe Browsing (GSB) under its SSL certificate issued by Google Trust Services (WE1). These indicators confirm its malicious intent and operational infrastructure. The domain is currently offline, reducing immediate user exposure. However, residual risk persists due to the domain’s recent creation, its presence on blocklists, and the potential for re-activation or migration to new infrastructure. Organizations should monitor for related IOCs, including the IP 180.178.44.100 and SSL certificate thumbprints, and update detection rules to prevent future compromise attempts. Users who accessed the domain should verify account activity and reset credentials as a precaution.
لقطة الأدلة المرسلة
- أُرسل
- سجلات الدفتر
- 1
- معرّف القضية
PD-20260107-42D459- عنوان الصفحة الملتقطة
- Shopee
- ملف PDF
- دليل PDF
النص الكامل للدليل
Acceptable Use Policy (AUP): The domain og6y7c.top is engaged in phishing activities, which constitutes a clear violation of your AUP prohibiting illegal activities and fraud.
Terms of Service (TOS): The use of this domain for deceptive practices allows for immediate suspension or termination of services under your TOS, as it undermines the integrity of your platform.
Applicable Laws (CN):
Cybersecurity Law of the People's Republic of China: This law prohibits the use of networks to engage in fraud and phishing activities, imposing strict penalties for violations.
Criminal Law of the People's Republic of China (Article 285): This article addresses computer fraud, making it illegal to deceive others for unlawful gains through electronic means.
Regulatory Note: Non-compliance with these policies and applicable laws may expose your organization to legal liabilities and regulatory scrutiny. Immediate action is required to mitigate these risks.
Data Coverage
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | og6y7c.top |
malicious | Sinkholed |
| OpenDNS | og6y7c.top |
phishing | Phishing Block |
| DigiCert UltraDNS | og6y7c.top |
malicious | Sinkholed |
| DNS0 Zero | og6y7c.top |
malicious | Sinkholed |
| DNS4EU | og6y7c.top |
malicious | Sinkholed |
| OpenDNS | pigeonteensindonesia.com |
phishing | Phishing Block |
| DigiCert UltraDNS | pigeonteensindonesia.com |
malicious | Sinkholed |
| DNS4EU | pigeonteensindonesia.com |
malicious | Sinkholed |
| Hagezi Threat Feed | pigeonteensindonesia.com |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026
المخطط الزمني للاكتشاف
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
لقطة محفوظة
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب