shopee8179[.]blogspot[.]com
“shopee”
Osservazione memorizzata
Contrasto dei titoli osservato
Riepilogo delle prove
PhishDestroy identifies shopee8179.blogspot.com as a confirmed fake Shopee login phishing portal designed to harvest user credentials and payment details. This Blogspot-hosted domain impersonates the legitimate Shopee e-commerce platform, leveraging the platform’s trusted branding to deceive visitors into entering sensitive login and payment information. The threat actor uses a spoofed checkout page resembling Shopee’s interface, likely embedded with a drainer script to siphon credentials and session tokens directly to a remote server. The domain was flagged for exact-match Brand Impersonation (Shopee), with indicators pointing to a credential harvesting operation aimed at Southeast Asian e-commerce users.
This domain was flagged with an elevated risk level and is currently active. Technical indicators include a VirusTotal detection score of 12 out of 95 security vendors, a resolved IP address of 172.217.16.161, and registration on Google’s Blogger platform. The domain resolves via a Google Trust Services SSL certificate, indicating HTTPS enforcement, which may increase user trust despite malicious intent. It appears on 1 active blocklist including OpenPhish, and was created as part of a larger campaign using seed identifier 993afa. The registrar is Google LLC via Blogger, and the site has been active for several weeks targeting ongoing phishing operations.
As of the latest scan, shopee8179.blogspot.com remains active and accessible. Immediate response actions include blocking the domain at network and endpoint levels, and updating firewall rules to deny traffic to 172.217.16.161. Users are advised to avoid accessing this domain and to verify any suspicious links using PhishDestroy’s lookup tool. While the current threat is elevated, the risk can be mitigated through proactive threat intelligence sharing and user awareness training focused on recognizing fake login portals. Remaining risk includes continued operation of the phishing page and potential expansion to other regional e-commerce brands.
Data Coverage
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | www.youtube.com/s/player/5e4f1adf/player_es6.vflset/en_us/base.js |
audit | Hunting_JS_WebAssembly |
| DNS4EU | shopee8179.blogspot.com |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 11/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of shopee8179.blogspot.com · checked Mar 26, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo