tiktokshopmail[.]help
“tiktokshopmail.help | 521: Web server is down”
tiktokshopmail.help — Não verificado. Representação da marca: TikTok; Tipo de golpe: Social Media Phishing. Resumo das evidências: VirusTotal 18/91 (ADMINUSLabs, AILabs (MONITORAPP), alphaMountain.ai, BitDefender, Chong Lua Dao); Spamhaus DBL_SPAM; PhishDestroy score 95/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain tiktokshopmail.help is currently identified as a brand impersonation threat targeting TikTok, a prominent social media platform. This domain was designed to mimic official TikTok communications, likely to deceive users into disclosing sensitive information or engaging with fraudulent content. As of the latest assessment, the domain has been taken offline, though prior activity suggests it was actively used in malicious campaigns. Analysis of technical indicators reveals significant red flags. The domain is flagged by 16 of 95 security vendors on VirusTotal, indicating widespread detection as malicious. It was registered on February 21, 2026, through the registrar WE1, a detail that may aid in tracking related infrastructure. The domain resolved to the IP address 172.67.136.194, which has been linked to other suspicious activities. Additionally, tiktokshopmail.help appears on two security blocklists and has been included in 13 threat intelligence pulses on AlienVault OTX, further corroborating its malicious nature. The SSL certificate associated with the domain is also issued by WE1, a non-standard certificate authority that may lack rigorous validation processes. At present, tiktokshopmail.help is offline, displaying a 521 error indicating the web server is down. However, the domain's prior activity and associations warrant continued vigilance. Organizations and individuals are advised to block this domain at the network level and monitor for any resurgence of activity. Users who may have interacted with this domain should immediately review their accounts for unauthorized access, enable multi-factor authentication, and report any suspicious activity to the targeted brand's official security channels. Proactive threat hunting for related indicators of compromise, such as the IP address 172.67.136.194, is recommended to mitigate potential risks from this campaign.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Inteligência forense
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo