shopee8179[.]blogspot[.]com
“shopee”
Збережене спостереження
Зафіксована відмінність заголовків
Зведення доказів
PhishDestroy identifies shopee8179.blogspot.com as a confirmed fake Shopee login phishing portal designed to harvest user credentials and payment details. This Blogspot-hosted domain impersonates the legitimate Shopee e-commerce platform, leveraging the platform’s trusted branding to deceive visitors into entering sensitive login and payment information. The threat actor uses a spoofed checkout page resembling Shopee’s interface, likely embedded with a drainer script to siphon credentials and session tokens directly to a remote server. The domain was flagged for exact-match Brand Impersonation (Shopee), with indicators pointing to a credential harvesting operation aimed at Southeast Asian e-commerce users.
This domain was flagged with an elevated risk level and is currently active. Technical indicators include a VirusTotal detection score of 12 out of 95 security vendors, a resolved IP address of 172.217.16.161, and registration on Google’s Blogger platform. The domain resolves via a Google Trust Services SSL certificate, indicating HTTPS enforcement, which may increase user trust despite malicious intent. It appears on 1 active blocklist including OpenPhish, and was created as part of a larger campaign using seed identifier 993afa. The registrar is Google LLC via Blogger, and the site has been active for several weeks targeting ongoing phishing operations.
As of the latest scan, shopee8179.blogspot.com remains active and accessible. Immediate response actions include blocking the domain at network and endpoint levels, and updating firewall rules to deny traffic to 172.217.16.161. Users are advised to avoid accessing this domain and to verify any suspicious links using PhishDestroy’s lookup tool. While the current threat is elevated, the risk can be mitigated through proactive threat intelligence sharing and user awareness training focused on recognizing fake login portals. Remaining risk includes continued operation of the phishing page and potential expansion to other regional e-commerce brands.
Data Coverage
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | www.youtube.com/s/player/5e4f1adf/player_es6.vflset/en_us/base.js |
audit | Hunting_JS_WebAssembly |
| DNS4EU | shopee8179.blogspot.com |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 12.08.2026
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of shopee8179.blogspot.com · checked Mar 26, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога