codashop[.]official-topup[.]com
“Buy Mobile Legends | Up to 2x Bonus Diamonds | Codashop”
codashop.official-topup.com has been identified as a confirmed brand impersonation phishing site, currently taken offline after posing as the legitimate Codashop platform to steal user credentials. The domain was created on December 26, 2025, and registered through Aceville Pte. Ltd., resolving to IP address 172.67.196.112. Security analysis reveals that 19 out of 95 VirusTotal vendors flagged this domain as malicious, and it appears on 1 security blocklist. The page title, "Buy Mobile Legends | Up to 2x Bonus Diamonds | Codashop," was designed to lure users into entering sensitive information under the guise of a promotional offer.
This brand impersonation campaign specifically targeted Codashop, a legitimate digital goods marketplace, by mimicking its branding and URL structure. The absence of an SSL certificate further underscores the fraudulent nature of the site. Despite being taken offline, the domain remains a significant threat due to its recent creation and the high number of security vendor flags. Users who may have interacted with the site are at risk of credential theft and potential financial loss.
PhishDestroy strongly advises all users to avoid any interaction with codashop.official-topup.com and to report similar domains to relevant authorities. If you have already visited the site or entered any personal information, change your passwords immediately and enable two-factor authentication on affected accounts. For ongoing protection, utilize reputable security tools and verify URLs before entering sensitive data.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Registration: official-topup.com
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For the registrable domain official-topup.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive