confirm-order2h5.shop
Appeared in the .shop zone on Monday, September 14, 2026; by the end of that day the census found redirects elsewhere. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
The name 'confirm-order2h5.shop' is a disposable order/delivery-confirmation lure with a random suffix on a cheap .shop TLD behind Cloudflare NS, and it currently cloaks by redirecting all visitors offsite to www.google.com — the Google branding is the destination's, not this domain's. This is the typical dormant/cloaked stage of an order-confirmation smishing campaign, but no deceptive content has been served yet, so evidence is not decisive.
The domain name 'confirm-order2h5.shop' is a typosquat/squat with lure words ('confirm', 'order') designed to deceive visitors into clicking it, but the domain itself serves no phishing page—it redirects directly to Google's legitimate homepage. This is a redirect squat: the attacker registered a deceptive name to capture clicks from victims expecting an order-confirmation page, then immediately sends them offsite. The squat's only plausible purpose is traffic theft or reputation manipulation, n
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Monday, September 14, 2026

Same data as JSON: /api/zone/domain/confirm-order2h5.shop. This page is not indexed by search engines and does not link to the site it describes.