shopee8179[.]blogspot[.]com
“shopee”
shopee8179.blogspot.com — Conteúdo indisponível. Representação da marca: Shopee; Tipo de golpe: E Commerce Scam. Resumo das evidências: VirusTotal 18/94 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); URLQuery 2 alerts; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 100/100. Registrador: Google Blogger.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
PhishDestroy identifies shopee8179.blogspot.com as a confirmed fake Shopee login phishing portal designed to harvest user credentials and payment details. This Blogspot-hosted domain impersonates the legitimate Shopee e-commerce platform, leveraging the platform’s trusted branding to deceive visitors into entering sensitive login and payment information. The threat actor uses a spoofed checkout page resembling Shopee’s interface, likely embedded with a drainer script to siphon credentials and session tokens directly to a remote server. The domain was flagged for exact-match Brand Impersonation (Shopee), with indicators pointing to a credential harvesting operation aimed at Southeast Asian e-commerce users.
This domain was flagged with an elevated risk level and is currently active. Technical indicators include a VirusTotal detection score of 12 out of 95 security vendors, a resolved IP address of 172.217.16.161, and registration on Google’s Blogger platform. The domain resolves via a Google Trust Services SSL certificate, indicating HTTPS enforcement, which may increase user trust despite malicious intent. It appears on 1 active blocklist including OpenPhish, and was created as part of a larger campaign using seed identifier 993afa. The registrar is Google LLC via Blogger, and the site has been active for several weeks targeting ongoing phishing operations.
As of the latest scan, shopee8179.blogspot.com remains active and accessible. Immediate response actions include blocking the domain at network and endpoint levels, and updating firewall rules to deny traffic to 172.217.16.161. Users are advised to avoid accessing this domain and to verify any suspicious links using PhishDestroy’s lookup tool. While the current threat is elevated, the risk can be mitigated through proactive threat intelligence sharing and user awareness training focused on recognizing fake login portals. Remaining risk includes continued operation of the phishing page and potential expansion to other regional e-commerce brands.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | www.youtube.com/s/player/5e4f1adf/player_es6.vflset/en_us/base.js |
audit | Hunting_JS_WebAssembly |
| DNS4EU | shopee8179.blogspot.com |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 6 identified
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of shopee8179.blogspot.com · checked Mar 26, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo