Analysis of hashopee.com indicates a high-risk phishing domain actively engaged in social engineering, as flagged by Google Safe Browsing on August 1, 2026. The domain was registered on July 31, 2026, through Dominet (HK) Limited, a registrar frequently associated with newly created fraudulent infrastructure. Infrastructure analysis reveals the domain resolves to the IP address 104.21.39.98, which is part of Cloudflare’s network, a common hosting choice for phishing sites due to its accessibility and obfuscation capabilities. Nameservers include leia.ns.cloudflare.com and noel.ns.cloudflare.com, alongside ns7.alidns.com and ns8.alidns.com, suggesting a hybrid DNS configuration that may complicate takedown efforts.
The domain appears on at least one security blocklist, specifically PhishDestroy, which has classified it as malicious. While VirusTotal scans from 91 vendors returned no detections as of the latest assessment, this absence does not confirm safety; phishing domains often evade initial detection due to their short-lived nature or targeted deployment. Google Safe Browsing explicitly flags the domain for social engineering, a classification that aligns with its recent registration and rapid appearance on blocklists. No specific brand impersonation or phishing kit details are available in the current intelligence, and the exact content of the site remains unanalyzed.
Defenders should treat this domain as an active threat, particularly given its recent creation and association with known phishing infrastructure. Organizations are advised to block the domain at the DNS or proxy level, monitor for connections to the IP 104.21.39.98, and alert users to the social engineering risk. Further investigation into the domain’s hosting patterns and potential ties to other malicious infrastructure is recommended.