gewwrvsk.shop
Appeared in the .shop zone on Wednesday, September 16, 2026; by the end of that day the census found active website about e-commerce & retail. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
Random-string domain on a brand-new .shop with a cookie-cutter storefront selling four generic items scraped from Amazon/Wish/Mercari/Poshmark, all add-to-cart forms posting to itself with hidden cart_token fields; the 'Secure PayPal Checkout' banner is a trust badge, not PayPal impersonation, so this is a throwaway fake-shop payment scam rather than credential phishing.
The page prominently advertises 'Secure PayPal Checkout' and mentions PayPal in the title context, but the domain gewwrvsk.shop is a random gibberish name with no association to PayPal. The page contains multiple forms (POST to self with hidden action/slug/cart_token fields) that create the sealed-room phishing pattern: credentials or payment data entered here would be captured by the attacker, not legitimately processed by PayPal. The all-offsite links (Amazon find, Wish find, Mercari find, Pos
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Wednesday, September 16, 2026

Same data as JSON: /api/zone/domain/gewwrvsk.shop. This page is not indexed by search engines and does not link to the site it describes.