tulsaking[.]shop
“Tulsa King Shop - Official Tulsa King Merchandise Store”
tulsaking.shop — 未验证. 品牌冒充:Backpack; 诈骗类型:Impersonation. 证据摘要: VirusTotal 0/91; URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 80/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy first observed tulsaking.shop on Aug 14, 2026. Stored content metadata identifies Backpack as the apparent target. The captured page title is “Tulsa King Shop - Official Tulsa King Merchandise Store”. Page analysis recorded additional brand references to Mastercard, PayPal, and Visa. Stored page analysis classifies the content as impersonation. Current evidence score: 80/100 (critical).
Positive findings are stored from 3 sources: MetaMask, SEAL, and URLQuery. MetaMask and SEAL listed the hostname in the separate external-blocklist snapshot on Aug 14, 2026 at 14:20 UTC. URLQuery recorded 1 threat-system alert on Aug 14, 2026 at 04:48 UTC. Non-positive and contextual checks: VirusTotal recorded 0 detections among 91 engines on Aug 14, 2026 at 05:17 UTC. AlienVault OTX listed 4 community pulse references (not vendor detections) on Aug 14, 2026 at 11:27 UTC. Google Safe Browsing returned no flag on Aug 14, 2026 at 11:26 UTC. URLScan completed without a malicious verdict (score 0) on Aug 14, 2026 at 11:08 UTC. The 0/91 VirusTotal snapshot and the positive findings above are conflicting observations from different sources or collection times.
The collector marked the hostname reachable on Aug 14, 2026 at 04:44 UTC, but did not retain the HTTP response code. At collection time, the hostname resolved to 5.252.154.209 on AS30860 (YURTEH-AS Virtual Systems LLC, UA). The recorded endpoint location is Kyiv, UA. The stored server header is BunnyCDN-ASB1-1310. DOM analysis on Aug 14, 2026 at 06:22 UTC returned 80/100. The evidence archive retains 4 visual captures from PhishDestroy, URLScan, URLQuery, and Cloudflare Radar. TLS metadata lists Let's Encrypt as the certificate issuer with validity through Oct 6, 2026; checked Aug 14, 2026 at 07:02 UTC.
The content indicators and 3 positive source findings support the current Backpack-themed impersonation classification.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | tulsaking.shop |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 7 identified
Vue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.
vuejs.org 置信度 100%Google Analytics is a free web analytics service that tracks and reports website traffic.
google.com 置信度 100%Livewire is a full-stack Laravel framework for building dynamic interfaces.
laravel-livewire.com 置信度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 置信度 100%VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of tulsaking.shop · checked Aug 14, 2026
证据与外部报告
PD-20260814-787B5B Recipient: abuse@wehostservers.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。