Analysis of the domain epiccheck.shop indicates active credential phishing infrastructure as of July 31, 2026. The domain is currently resolving to the IP address 193.187.110.3 and has been flagged by one security blocklist, specifically PhishDestroy. Nameserver records point to a.dnspod.com, b.dnspod.com, and c.dnspod.com, a configuration commonly associated with domains registered through DNSPod services, though the registrar details remain unconfirmed in available intelligence. VirusTotal telemetry shows that 91 vendors have scanned the domain, with no detections reported at the time of this assessment. The absence of detections does not confirm the domain's safety, particularly as phishing domains often evade initial scans through cloaking or delayed malicious behavior.
The domain remains active, and defenders should treat it as a potential threat until further analysis confirms otherwise. Infrastructure analysis reveals no additional context regarding the targeted brand, scam type, or phishing kit in use. The exact content hosted on the domain has not been analyzed, and no page title or HTTP response data is available to determine the specific lure or victim profile. The IP address 193.187.110.3 has not been linked to other known malicious domains in public threat feeds at this time, though defenders are advised to monitor for associations with emerging campaigns.
Defenders should implement blocking at the DNS or network level for epiccheck.shop and its resolving IP address. Security teams are encouraged to conduct retrospective log analysis to identify any prior interactions with the domain or IP within their environments. If additional telemetry becomes available—such as brand impersonation details, phishing kit signatures, or user reports—further action may be warranted. Continuous monitoring is recommended, as phishing domains frequently shift infrastructure or resurface under new registrations.