shopee-tbk777[.]blogspot[.]com
“Hadiah Shopee 2020”
shopee-tbk777.blogspot.com — Контент недоступний. Уособлення бренду: Google; Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 18/91 (Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. Реєстратор: Google Blogger.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, shopee-tbk777.blogspot.com, is identified as a phishing resource impersonating the Shopee e-commerce platform. Analysis indicates the threat type is brand impersonation, specifically designed to deceive users into believing they are interacting with a legitimate Shopee promotion. The page title, Hadiah Shopee 2020, suggests an attempt to lure victims with fake prize offers, a common tactic in credential harvesting and social engineering campaigns. No evidence of a cryptocurrency drainer kit or direct financial exfiltration script was observed in initial analysis, though further forensic examination of archived content is recommended to confirm payload behavior. Infrastructure analysis reveals the domain was registered through Google Blogger, a platform frequently abused for hosting low-cost phishing pages due to its accessibility and minimal verification requirements. The domain resolves to the IP address 142.250.31.132, geolocated in Germany under AS15169, assigned to Google LLC. VirusTotal detection metrics report 18 out of 95 security vendors flagging the domain as malicious, indicating moderate but not universal recognition of the threat. The domain appears on a single security blocklist, specifically PhishDestroy, and no Google Safe Browsing (GSB) listing was confirmed at the time of analysis. No historical registration data or creation date is available due to the use of a subdomain on a third-party platform, limiting temporal attribution. Current status indicates the domain has been taken offline, likely following abuse reports or automated takedown procedures. While the immediate threat has been mitigated, residual risk persists due to potential rehosting on alternative subdomains or platforms. Users who interacted with the page prior to takedown may remain vulnerable to follow-up attacks, including credential reuse or targeted phishing via harvested contact details. Organizations are advised to monitor for indicators of compromise associated with this campaign, including the IP 142.250.31.132 and the Hadiah Shopee 2020 page title. End users should be educated on recognizing brand impersonation tactics, particularly those leveraging fake prize notifications, and instructed to verify promotional offers through official vendor channels.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 5 identified
Blogger is a blog-publishing service that allows multi-user blogs with time-stamped entries.
www.blogger.com 100% впевненостіJava is a class-based, object-oriented programming language that is designed to have as few implementation dependencies as possible.
java.com 100% впевненостіOpenGSE is a test suite used for testing servlet compliance. It is deployed by using WAR files that are deployed on the server engine.
code.google.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога