app[.]hdmkf[.]com
“TikTok Shop”
Analysis of the domain app.hdmkf.com indicates a high‑risk brand‑impersonation operation targeting the brand Base. The domain was registered on May 23, 2025 through Alibaba Cloud Computing Ltd. d/b/a HiChina (www.net.cn) and is served by the nameservers dns3.hichina.com, dns4.hichina.com, ns1.judns.com and ns2.judns.com. Infrastructure resolution points to the IP address 137.220.152.151, which is allocated to AS4907 BGPNET PTE. LTD. in Hong Kong.
No SSL certificate is present, suggesting the site was delivered over HTTP only. The page title returned from the live site was "TikTok Shop," but the content has not been captured for further forensic review. Security telemetry shows the domain appears on a single blocklist and has been actively blocked by PhishDestroy. Google Safe Browsing classifies the domain as a social‑engineering threat, and VirusTotal records 15 detections out of 95 scanned security vendors, reinforcing the malicious assessment. Reputation services assign extremely low trust scores: Gridinsoft reports 0 / 100 and Scamadviser 1 / 100, reflecting a lack of legitimacy.
Current status is offline, which may be temporary or a takedown attempt; however, the underlying infrastructure could be reused for future campaigns. Defenders should continue to monitor the associated IP range and the registrar’s name servers for new domains that exhibit similar registration patterns. Blocking the domain at network perimeter, updating URL filtering lists, and incorporating the IP address into threat‑intel feeds are recommended. Because the site’s content has not been archived, further analysis of the payload and any credential‑harvesting mechanisms remains uncertain and should be pursued if the domain resurfaces.
Security Signals
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Registration: hdmkf.com
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For the registrable domain hdmkf.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive