janopo.shop is currently listed as an active generic phishing infrastructure observed on July 31 2026. The domain is delegated to the DNSPod name servers a.dnspod.com, b.dnspod.com and c.dnspod.com and resolves to the IPv4 address 193.187.110.3. PhishDestroy has already added the domain to its block list, and an additional security blocklist also flags it, indicating that at least two independent threat‑filtering sources have identified malicious intent. The domain was submitted to VirusTotal where 91 anti‑malware engines evaluated the associated host; none of the engines reported a detection, but the absence of a flag does not constitute a safety assurance.
No public SSL certificate details, HTTP response codes, or page‑title information are available in the current intelligence set, leaving the surface‑level characteristics of the hosted content unverified. The limited evidence points to a classic phishing deployment that leverages a short‑lived domain and a shared DNS hosting service. The IP address 193.187.110.3 is not currently associated with a known content delivery network or reputable hosting provider, which further raises suspicion. Because the domain is still resolving and actively serving content, defenders should treat it as hostile.
Recommended actions include adding janopo.shop to network‑level deny lists, blocking outbound connections to the associated IP, and monitoring DNS queries for the three dnspod.com name servers for potential future look‑alikes. Continuous re‑scanning of the domain through multi‑engine services is advised to capture any later payload or technique changes. Organizations that employ email filtering should ensure that URLs pointing to janopo.shop are quarantined, and incident response teams should be prepared to investigate any credential‑theft reports that reference this domain.