shoptks[.]xyz
shoptks.xyz — 内容不可用 (HTTP 502). 证据摘要: VirusTotal 18/93 (alphaMountain.ai, BitDefender, Certego, CRDF, CyRadar); PhishDestroy score 95/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, shoptks.xyz, is identified as a credential harvesting phishing site designed to mimic legitimate retail platforms. Analysis indicates the infrastructure was specifically engineered to capture user login credentials, payment details, and personal information through fraudulent checkout or account management interfaces. The domain employs social engineering tactics, including replica branding and urgency-driven messaging, to deceive visitors into submitting sensitive data. Infrastructure analysis reveals the domain was registered on February 21, 2026, and resolves to IP address 8.216.39.39, hosted under AS45102 (Alibaba (US) Technology Co., Ltd.) in Japan. Technical indicators include an SSL certificate issued under the R13 root, a configuration commonly observed in low-effort phishing campaigns. The domain is flagged by 18 of 95 security vendors on VirusTotal and appears on one operational blocklist. Detection systems previously classified the domain as offline, though historical activity suggests intermittent reactivation for targeted campaigns. Users who visited shoptks.xyz should immediately revoke any entered credentials from associated accounts, particularly those linked to financial services or e-commerce platforms. Monitor accounts for unauthorized transactions or login attempts, and enable multi-factor authentication where available. Network administrators are advised to block the domain and its resolving IP (8.216.39.39) at the perimeter, and review logs for connections to this infrastructure. If payment details were submitted, contact financial institutions to initiate fraud mitigation procedures.
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。