shopei[.]vip
“Suspected phishing site | Cloudflare”
shopei.vip — सामग्री अनुपलब्ध (HTTP 502). घोटाले का प्रकार: Generic Phishing. साक्ष्य सारांश: VirusTotal 17/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 4 alerts; Google Safe Browsing flagged; 2 external blocklist matches (MetaMask, SEAL); CF Radar malicious; PhishDestroy score 100/100. रजिस्ट्रार: Gname.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
This domain, shopei.vip, is actively engaged in phishing operations designed to mimic legitimate e-commerce checkout processes, likely targeting users during payment transactions. Analysis indicates the site presents fraudulent payment forms to harvest credit card details, login credentials, and personal information under the guise of a trusted shopping platform. The infrastructure is engineered to deceive users into entering sensitive data, which is then exfiltrated to attacker-controlled servers for financial fraud or identity theft. Infrastructure analysis reveals multiple high-confidence technical indicators. The domain was registered on March 12, 2026, through Gname.com Pte. Ltd., a registrar frequently associated with malicious registrations. It resolves to the IP address 104.21.74.237, hosted on AS13335 (Cloudflare, Inc.), a network commonly leveraged to obfuscate attacker infrastructure. Detection metrics further substantiate the threat: VirusTotal reports 17 out of 95 security vendors flagging the domain as malicious, while three independent security blocklists—including PhishDestroy, MetaMask, and SEAL—have issued active warnings. The SSL certificate, issued by Let’s Encrypt (serial number E7), provides encrypted connections but does not validate legitimacy, as phishing sites routinely abuse free certificate authorities to appear trustworthy. Users who have visited shopei.vip or entered credentials on the site should immediately cease all interaction and take corrective measures. All exposed passwords, payment details, and personal information must be considered compromised and should be changed from a secure, unaffected device. Financial institutions should be notified to monitor for unauthorized transactions, and credit reports should be reviewed for signs of identity theft. Browser caches and cookies should be cleared to remove any residual tracking mechanisms. Given the domain’s high-risk classification and active status, organizations are advised to implement network-level blocking of 104.21.74.237 and shopei.vip to prevent further exposure.
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | shopei.vip |
malicious | Sinkholed |
| Hagezi Threat Feed | shopei.vip |
malicious | Sinkholed |
| DigiCert UltraDNS | shopei.vip |
malicious | Sinkholed |
| DNS4EU | shopei.vip |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
तकनीकें · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
वायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।