og6y7c[.]top
“Shopee”
og6y7c.top — Контент недоступний (HTTP 502). Уособлення бренду: Backpack; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 18/93 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CRDF); URLQuery 9 alerts; PhishDestroy score 95/100. Реєстратор: Namemart.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, og6y7c.top, is flagged for brand impersonation targeting the e-commerce platform Shopee, specifically mimicking backpack product pages. Analysis indicates the domain was designed to deceive users into believing they were interacting with legitimate Shopee listings, likely to harvest credentials, payment details, or distribute malware. No specific drainer kit signatures were identified, but the page title explicitly matched Shopee’s branding, suggesting a focused phishing campaign. Infrastructure analysis reveals the domain resolved to IP 180.178.44.100, hosted on AS45753 (Netsec Limited) in Hong Kong. It was registered via Namemart Limited on April 8, 2025, and achieved a VirusTotal detection score of 18/95 security vendors. The domain appeared on one security blocklist and was blocked by Google Safe Browsing (GSB) under its SSL certificate issued by Google Trust Services (WE1). These indicators confirm its malicious intent and operational infrastructure. The domain is currently offline, reducing immediate user exposure. However, residual risk persists due to the domain’s recent creation, its presence on blocklists, and the potential for re-activation or migration to new infrastructure. Organizations should monitor for related IOCs, including the IP 180.178.44.100 and SSL certificate thumbprints, and update detection rules to prevent future compromise attempts. Users who accessed the domain should verify account activity and reset credentials as a precaution.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | og6y7c.top |
malicious | Sinkholed |
| OpenDNS | og6y7c.top |
phishing | Phishing Block |
| DigiCert UltraDNS | og6y7c.top |
malicious | Sinkholed |
| DNS0 Zero | og6y7c.top |
malicious | Sinkholed |
| DNS4EU | og6y7c.top |
malicious | Sinkholed |
| OpenDNS | pigeonteensindonesia.com |
phishing | Phishing Block |
| DigiCert UltraDNS | pigeonteensindonesia.com |
malicious | Sinkholed |
| DNS4EU | pigeonteensindonesia.com |
malicious | Sinkholed |
| Hagezi Threat Feed | pigeonteensindonesia.com |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
PD-20260107-42D459 Recipient: hksupport@wdomain.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога