ptshopee617[.]blogspot[.]com
“SHOPEE”
Kaydedilmiş gözlem
Gözlemlenen başlık farkı
This domain, ptshopee617.blogspot.com, is identified as a generic phishing site targeting users of the e-commerce platform Shopee. Analysis confirms the domain was designed to mimic legitimate Shopee login or checkout pages, likely aiming to harvest user credentials, payment details, or personal information. The page title explicitly displays 'SHOPEE,' reinforcing the impersonation attempt. No specific drainer kit signatures were detected in the initial scan, though the use of Blogger as a hosting platform is a common tactic to evade detection and leverage trusted infrastructure. Infrastructure analysis reveals the following technical indicators: the domain is flagged by 19 out of 95 security vendors on VirusTotal, indicating broad consensus on its malicious nature. It is registered through Google Blogger, a free platform often exploited for phishing due to its accessibility and SSL support. The domain resolves to the IP address 142.251.16.132, associated with Google’s infrastructure, and employs an SSL certificate issued by Google Trust Services. Additional technologies detected include Java, Python, OpenGSE, and HTTP/3, which may be used to enhance the site’s functionality or obfuscate malicious activity. The domain appears on one security blocklist and has a Gridinsoft trust score of 0/100, further confirming its high-risk status. No creation date is publicly available due to the use of Blogger’s subdomain structure, though the domain’s recent takedown suggests it was operational for a limited period. As of the latest assessment, ptshopee617.blogspot.com has been taken offline, likely following reports to the hosting provider or automated takedown mechanisms. However, the elevated risk persists due to the potential for the threat actors to re-deploy the phishing infrastructure under a new subdomain or domain. Users who interacted with the site should immediately reset credentials for Shopee and any other accounts where the same login details were reused. Organizations are advised to block the domain and its associated IP address (142.251.16.132) at the network level to prevent accidental access. Monitoring for similar subdomains on Blogger or other free hosting platforms is recommended, as this tactic remains prevalent in phishing campaigns.
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 kaynak · 10.08.2026 tarihinde eşitlendi
Tespit zaman çizelgesi
Kaydedilmiş gözlemler kronolojik sıradadır.
-
VirusTotal
VirusTotal: 13 → 19
Teknolojiler
6 yüksek güvenli teknoloji belirlendi
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of ptshopee617.blogspot.com · checked Jun 26, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin