# PhishDestroy threat dossier — betterthanshopee.online ================================================================ Fetched: 2026-07-23 03:39:22 UTC Canonical: https://phishdestroy.io/domain/betterthanshopee.online/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Brand Impersonation Targeted brand: ShopeePay Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users (type: content_divergence) (score: 2/6) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain Flagging vendors: Gridinsoft Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.239.193.67 (US, Chicago) ASN: ASAS63949 AKAMAI-LINODE-AP - Akamai Connected Cloud, SG Hosting org: AS63949 Akamai Connected Cloud Registrar: GMO Internet, Inc. Nameservers: ns1.gm111.parklogic.com, ns1.parklogic.com, ns2.gm111.parklogic.com, ns2.parklogic.com Registered: 2025-06-03 Expires: 2027-06-03 Page title: Redirecting... ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE1 Expires: 2026-10-03 Status: INVALID chain Fingerprint: a28452af9c7dfede399d106f1fd8e3b9971c0f3d76c8a9159ec34da969c91f5b ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-06-03 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-06 16:49:36 UTC (by PhishDestroy tracker) Last verified: 2026-07-23 04:20:28 UTC Neutralised: 2026-07-09 12:38:57 UTC Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f37e7-310d-758a-808c-c8bdf5ba4d05/ Wayback Machine: https://web.archive.org/web/*/betterthanshopee.online crt.sh CT logs: https://crt.sh/?q=%25.betterthanshopee.online Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=betterthanshopee.online AlienVault OTX: https://otx.alienvault.com/indicator/domain/betterthanshopee.online URLhaus: https://urlhaus.abuse.ch/host/betterthanshopee.online/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-06 16:54:44 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] betterthanshopee.online Safety Check — ShopeePay Brand This domain is currently under investigation for brand impersonation, specifically targeting ShopeePay, a recognized digital payment service. The threat type involves unauthorized replication of branding elements to deceive users into divulging sensitive credentials or financial information. Analysis indicates the domain remains active, with no prior history of malicious activity but exhibiting high-risk characteristics due to its recent creation and impersonation tactics. Infrastructure analysis reveals the following technical indicators: the domain betterthanshopee.online was registered on June 03, 2025, through GMO Internet, Inc., and resolves to the IP address 172.234.27.233. VirusTotal reports 0 out of 95 security vendors flagging the domain as malicious, suggesting it has not yet been widely detected. The SSL certificate is issued by Let's Encrypt, a common provider for both legitimate and fraudulent sites. The page title 'Redirecting...' may indicate an attempt to obscure the final destination or facilitate unauthorized redirects to phishing pages. No blocklist entries or low trust scores were identified at the time of assessment, but the domain's infrastructure aligns with patterns observed in brand impersonation campaigns. Mitigation steps specific to this threat type include immediate monitoring of network traffic for connections to 172.234.27.233 or the domain itself, particularly within environments where ShopeePay is utilized. Organizations should implement DNS-based blocking to prevent resolution of betterthanshopee.online and conduct internal awareness campaigns to educate users about brand impersonation risks. Security teams are advised to analyze HTTP headers and redirect chains associated with the domain for signs of credential harvesting or malicious payload delivery. Given the domain's recent creation and lack of prior detections, continuous monitoring for updated threat intelligence is recommended to assess evolving risks. [Updates since narrative was generated:] - Public blocklists: now listed on 1 feed ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: a28452af9c7dfede399d106f1fd8e3b9971c0f3d76c8a9159ec34da969c91f5b ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/betterthanshopee.online/ JSON API: https://api.destroy.tools/v1/check?domain=betterthanshopee.online Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 188,607 domains (58,669 alive under monitoring, 128,313 confirmed takedowns/dead). Site: https://phishdestroy.io