ptshopee617[.]blogspot[.]com
“SHOPEE”
ملاحظة محفوظة
تباين العناوين المرصود
ملخص الأدلة
This domain, ptshopee617.blogspot.com, is identified as a generic phishing site targeting users of the e-commerce platform Shopee. Analysis confirms the domain was designed to mimic legitimate Shopee login or checkout pages, likely aiming to harvest user credentials, payment details, or personal information. The page title explicitly displays 'SHOPEE,' reinforcing the impersonation attempt. No specific drainer kit signatures were detected in the initial scan, though the use of Blogger as a hosting platform is a common tactic to evade detection and leverage trusted infrastructure. Infrastructure analysis reveals the following technical indicators: the domain is flagged by 19 out of 95 security vendors on VirusTotal, indicating broad consensus on its malicious nature. It is registered through Google Blogger, a free platform often exploited for phishing due to its accessibility and SSL support. The domain resolves to the IP address 142.251.16.132, associated with Google’s infrastructure, and employs an SSL certificate issued by Google Trust Services. Additional technologies detected include Java, Python, OpenGSE, and HTTP/3, which may be used to enhance the site’s functionality or obfuscate malicious activity. The domain appears on one security blocklist and has a Gridinsoft trust score of 0/100, further confirming its high-risk status. No creation date is publicly available due to the use of Blogger’s subdomain structure, though the domain’s recent takedown suggests it was operational for a limited period. As of the latest assessment, ptshopee617.blogspot.com has been taken offline, likely following reports to the hosting provider or automated takedown mechanisms. However, the elevated risk persists due to the potential for the threat actors to re-deploy the phishing infrastructure under a new subdomain or domain. Users who interacted with the site should immediately reset credentials for Shopee and any other accounts where the same login details were reused. Organizations are advised to block the domain and its associated IP address (142.251.16.132) at the network level to prevent accidental access. Monitoring for similar subdomains on Blogger or other free hosting platforms is recommended, as this tactic remains prevalent in phishing campaigns.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
المخطط الزمني للاكتشاف
-
VirusTotal
13 ← 19
التقنيات
حُدّدت ٦ تقنيات عالية الثقة
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of ptshopee617.blogspot.com · checked Jun 26, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب