Highscore 55 · flagged Monday, September 28, 2026

https-admin-shopify-com-store-egwnwt-1n.store

Appeared in the .store zone on Monday, September 28, 2026; by the end of that day the census found other. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

brand in the name
matched: shopify
+30
many hyphens
matched: 6
+6
very long name
matched: 39
+4
brand plus digits
matched: https-admin-shopify-com-store-egwnwt-1n
+8
brand name and brand-styled page
matched: shopify
+15
Registrar
—
Nameserver provider
Nameservers
getstore.mars.orderbox-dns.com, getstore.venus.orderbox-dns.com
First-day state
other
HTTP status
409
Page title
DNS resolution error | https-admin-shopify-com-store-egwnwt-1n.store | Cloudflare
Has a form
no
Brand echoed
shopify

Model opinions

Second opinionlooks like abusetarget: Shopifyconfidence 80%· claude-opus-5-5

The name 'https-admin-shopify-com-store-egwnwt-1n.store' spells out the Shopify merchant admin URL (admin.shopify.com/store/<id>), a pattern whose only plausible purpose is deceiving Shopify store owners. There is no page content yet (only a Cloudflare 1001 DNS error), so this is a brand-squat staged for likely phishing rather than confirmed credential capture.

First passlooks like abusetarget: Shopifyconfidence 92%· claude-haiku-4-5

The domain name impersonates Shopify's admin interface (https-admin-shopify-com-store-*) with a typosquat structure designed to deceive users into believing they are accessing Shopify's legitimate admin portal. The 409 error and Cloudflare DNS resolution failure indicate the domain was registered but not properly configured, consistent with a squat campaign awaiting content deployment for phishing or credential harvesting.

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

Same data as JSON: /api/zone/domain/https-admin-shopify-com-store-egwnwt-1n.store. This page is not indexed by search engines and does not link to the site it describes.