shopee8179[.]blogspot[.]com
“shopee”
已存储的观测记录
观测到的标题差异
证据摘要
PhishDestroy identifies shopee8179.blogspot.com as a confirmed fake Shopee login phishing portal designed to harvest user credentials and payment details. This Blogspot-hosted domain impersonates the legitimate Shopee e-commerce platform, leveraging the platform’s trusted branding to deceive visitors into entering sensitive login and payment information. The threat actor uses a spoofed checkout page resembling Shopee’s interface, likely embedded with a drainer script to siphon credentials and session tokens directly to a remote server. The domain was flagged for exact-match Brand Impersonation (Shopee), with indicators pointing to a credential harvesting operation aimed at Southeast Asian e-commerce users.
This domain was flagged with an elevated risk level and is currently active. Technical indicators include a VirusTotal detection score of 12 out of 95 security vendors, a resolved IP address of 172.217.16.161, and registration on Google’s Blogger platform. The domain resolves via a Google Trust Services SSL certificate, indicating HTTPS enforcement, which may increase user trust despite malicious intent. It appears on 1 active blocklist including OpenPhish, and was created as part of a larger campaign using seed identifier 993afa. The registrar is Google LLC via Blogger, and the site has been active for several weeks targeting ongoing phishing operations.
As of the latest scan, shopee8179.blogspot.com remains active and accessible. Immediate response actions include blocking the domain at network and endpoint levels, and updating firewall rules to deny traffic to 172.217.16.161. Users are advised to avoid accessing this domain and to verify any suspicious links using PhishDestroy’s lookup tool. While the current threat is elevated, the risk can be mitigated through proactive threat intelligence sharing and user awareness training focused on recognizing fake login portals. Remaining risk includes continued operation of the phishing page and potential expansion to other regional e-commerce brands.
Data Coverage
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | www.youtube.com/s/player/5e4f1adf/player_es6.vflset/en_us/base.js |
audit | Hunting_JS_WebAssembly |
| DNS4EU | shopee8179.blogspot.com |
malicious | Sinkholed |
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of shopee8179.blogspot.com · checked Mar 26, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控