Highscore 55 · flagged Sunday, September 20, 2026

httpsadminshopifycomstoremindrest-9089accessaccount.online

Appeared in the .online zone on Sunday, September 20, 2026; by the end of that day the census found boilerplate page. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

brand in the name
matched: shopify
+14
lure words (login, verify, secure…)
matched: access,account
+32
very long name
matched: 51
+4
brand plus digits
matched: httpsadminshopifycomstoremindrest-9089accessaccount
+8
identical page on many newborns
matched: 49 identical pages
+10
Registrar
Nameserver provider
Nameservers
dns1.nominalia.com, dns2.nominalia.com
First-day state
boilerplate page
HTTP status
503
Page title
SSL Error
Has a form
no
Brand echoed
shopify

Model opinions

Second opinionlooks like phishingtarget: Shopifyconfidence 75%· claude-opus-5

The domain is a full fake URL string ('https admin.shopify.com /store/mindrest-9089 /access/account') designed to render in a mail client or address bar as a legitimate Shopify admin account link; its only plausible use is credential capture from a specific merchant, and the scorer notes 49 identical sibling pages indicating a brand-page campaign. Content is currently just an 'SSL Error' hosting placeholder, so the kit is staged but not yet live.

First passlooks like abuseconfidence 92%· claude-haiku-4-5

The domain is a Shopify typosquat (httpsadminshopify...) with lure words ('access', 'account') in a 51-character name designed to mimic admin portal URLs. Currently showing a boilerplate SSL error page with no functional phishing content, but the domain registration pattern (49 identical pages in cluster, brand+digits construction) and infrastructure indicate a prepared phishing infrastructure awaiting activation rather than active impersonation.

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Sunday, September 20, 2026

Screenshot of httpsadminshopifycomstoremindrest-9089accessaccount.online taken by the zone census on 2026-09-20

Same data as JSON: /api/zone/domain/httpsadminshopifycomstoremindrest-9089accessaccount.online. This page is not indexed by search engines and does not link to the site it describes.