Analysis of big-shopee52.blogspot.com indicates an active phishing campaign leveraging Google's Blogspot platform to impersonate the Shopee e-commerce brand. As of July 30, 2026, the domain remains operational with no nameservers configured (NS_NOT_FOUND), a common indicator of rapid deployment tactics. Infrastructure analysis reveals the domain resolves to IP 142.251.14.132, which belongs to Google LLC, consistent with Blogspot hosting origins. Detection data from VirusTotal shows 6 of 91 security vendors flagging the domain as malicious, while it appears on one security blocklist and is specifically blocked by PhishDestroy.
The registrar is confirmed as Google LLC, aligning with the hosting infrastructure. Defenders should note that the domain's reliance on a legitimate hosting provider complicates traditional takedown approaches, requiring direct abuse reporting to Google. The absence of nameserver records suggests the domain may have been recently activated or improperly configured, potentially to evade initial detection.
While the exact content of the phishing page is not yet analyzed, the domain name and detection patterns strongly indicate a Shopee-branded credential harvesting or payment fraud scheme. Organizations are advised to implement immediate network-level blocking for 142.251.14.132 and the domain, while monitoring for related subdomains or IP shifts. Given the domain's persistence despite detection flags, security teams should prioritize endpoint protection rules that detect Blogspot-based phishing attempts, particularly those targeting e-commerce credentials.