DANGEROUS

Brand impersonation — not the real site

3 of 92 antivirus engines flag this page as malicious. This page is styled as a brand but is not the brand's real site. Go to the official site directly, and treat any download, login, or payment request here as unsafe.

Security Review

Is nyjfv.xyz legit or a scam?

Our verdict:Dangerous· 1/100

Malicious SHEIN clone hosting fake promotional campaigns; flagged by antivirus engines and sandbox analysis.

nyjfv.xyzScanned 1h ago
0
Trust score
DANGEROUS
Heuristics 0·MT 18
Category tags
fake shopclone site#Fake Shop#Clone Site#Fake Giveaway92% MT confidence
Warning signals (1)

These checks passed — but they don't clear the site. A clean antivirus result, valid SSL, and a calm server only mean it isn't hosting malware; they say nothing about whether the business is real. This verdict is based on the site's conduct and content, not a malware detection.

View density

Analysis Summary

Threat Intelligence
5/92
Engines flagged this URL
Domain Age
6 months old
Registered Dec 6, 2025
MT Intelligence
Dangerous
Critical likelihood · 92% confidence

MT Intelligence

Advanced threat intelligence
MT Security Analyst
Critical scam likelihoodengineMT · Guardiantrust18/100
MT AgentLive web researchVisual inspectionNetwork correlation
0%
Confidence
Our antivirus network detected this domain as malicious across multiple engines, with ADMINUSLabs and Chong Lua Dao marking it as outright malicious and Fortinet identifying phishing behaviour. The domain is a confirmed clone of SHEIN, hosting paths like /Taawon-Promo and /Sheln-Promo that mimic legitimate discount campaigns — a classic tactic for credential harvesting or payment fraud. Sandbox submissions explicitly label the site as malicious, and the domain has been used in social-media posts promoting fake giveaways in Arabic-language markets. No legitimate business registration, company records, or positive reviews exist for this domain. The .xyz TLD is heavily over-represented in scam operations, and the 184-day age combined with zero traffic ranking and no legitimate presence confirms this is a purpose-built fraud operation.
Full dossier
Analysis complete

Page Content

The domain hosts promotional paths (/Taawon-Promo, /Sheln-Promo) designed to mimic SHEIN discount campaigns. These pages are used in social-media marketing to lure users into fake giveaways or promotional schemes, a common vector for credential and payment-data theft.

Infrastructure

Hosted on IP 148.72.0.254 with clean abuse history (0/100 abuse score). SSL certificate is valid (Let's Encrypt, 61 days to expiry). No redirects or domain-spoofing tactics detected at the DNS level.

Domain History

Registered 184 days ago via GoDaddy with privacy protection disabled. The domain shows no legitimate business presence, no company registration in any jurisdiction, and zero global traffic ranking. Age and operational pattern are consistent with a purpose-built scam farm.

Web Reputation

Flagged as malicious by ADMINUSLabs and Chong Lua Dao; identified as phishing by Fortinet; marked suspicious by alphaMountain.ai and Forcepoint ThreatSeeker. Sandbox analysis explicitly labels URLs on this domain as malicious. No positive reviews or legitimate business records found on any independent aggregator or business-registration database.

Risk Factors
7
  • Confirmed clone of SHEIN with promo-path mimicry designed to harvest credentials or payment data.
  • 5 antivirus engines flagged the domain as malicious or suspicious, including tier-1 detectors.
  • Sandbox analysis explicitly marked URLs on this domain as malicious.
  • No legitimate business registration, company records, or positive reviews in any database.
  • Used in social-media campaigns promoting fake giveaways in Arabic-language markets.
  • .xyz TLD is heavily over-represented in scam and fraud operations.
  • Zero global traffic ranking and no legitimate operational footprint.
Positive Signals
3
  • Valid SSL certificate issued by Let's Encrypt.
  • Hosting IP has clean abuse history (0 reports, 0/100 abuse score).
  • No cross-domain redirects or homoglyph-spoofing tactics detected.
AI Recommendation
Do not visit this site or enter any personal, payment, or credential information. If you encountered this domain via social media, report the post to the platform. If you have already entered credentials or payment data, contact your bank and payment provider immediately.
Scam network detected
1 linked domain correlated

This domain is a confirmed clone of SHEIN, using promo-path mimicry and fake-giveaway campaigns to harvest credentials or payment data. The pattern is consistent with scam-farm operations targeting e-commerce shoppers.

shein.com
Next-gen fraud intelligence
Evidence-backedCross-checked

Website Preview

Screenshot of nyjfv.xyz
LIVE RENDER
nyjfv.xyz

Automated page render — captured in a safe sandbox. What an ordinary visitor would see when loading the site.

Web Research Findings

Our live research agent queries scam-report databases, consumer-review sites, news coverage, and general web search for nyjfv.xyz, then cross-checks business-registration records and look-alike domain patterns. Everything below is pulled from what it actually found.

Domain age
6 months
Registered Dec 2025
Business registration
No public record found
Could not match the site to a registered company — common for small sites.
Clone check
Clones shein.com
The page impersonates a well-known brand's site.
Typosquat check
No look-alike match
The domain doesn't resemble any well-known brand's spelling.
Web mentions
2 scam reports · 1 complaint
Key findings
6 headline facts from open-web research
  • Domain nyjfv.xyz is 184 days old and hosts paths such as /Taawon-Promo and /Sheln-Promo.
  • Submitted to Hybrid Analysis as a URL sample and explicitly labeled "malicious" in their sandbox submissions list.
  • Used in Facebook and Instagram posts promoting "Taawon-Promo" (appears to be Arabic-language marketing or giveaway bait).
  • No legitimate business records, reviews, or company information found associated with the domain.
  • .xyz TLD frequently associated with scam and fraud sites according to multiple bank and consumer warnings.
  • No entries on major review platforms (Trustpilot, ScamAdviser, ScamDoc) or Reddit discussions specific to this domain.
Scam reports (2)
Direct quotes from public scam databases, forums, and news.
  • Hybrid Analysisopen

    "https://nyjfv.xyz/Taawon-promo, malicious"

  • Hybrid Analysisopen

    "Submission name: hxxps://nyjfv.xyz/Taawon-Promo ... suspicious AV Detection"

Impersonation / typosquat
Clone of shein.com

Path /Sheln-Promo and similar promo links mimic SHEIN discount or promo campaigns; common tactic for fake shopping or airdrop scams

Research summary
Narrative write-up from our AI analyst, grounded on the facts above

Sandbox analysis flagged URLs on nyjfv.xyz as malicious, with submissions explicitly labeling the domain as a malicious resource. The domain has been used in Facebook and Instagram posts promoting fake promotional campaigns (Taawon-Promo, Sheln-Promo) targeting Arabic-language audiences. No legitimate business records, company registrations, or positive reviews were found on any consumer-review platform or business-registration database. The .xyz TLD is flagged by multiple financial institutions and consumer-protection agencies as over-represented in scam and fraud operations.

Scam Network Intelligence

Cross-site correlation

This site shares signals with a broader cluster

High correlation

Many scams don't operate alone. We correlate third-party scripts, hosting infrastructure, brand-impersonation signals, and the AI evidence package to detect when a site is part of a broader scam network.

Suspicion score
0/100
ClearLowModerateHighCritical
Evidence (2)
  • Evidence confirms this site is a clone of shein.com.
  • Short name on low-trust .xyz TLD — over-represented on scam farms.
Linked signals (2)
Clone of shein.comPattern · LOW Trust TLD

Antivirus Engines

Detection matrix · live
5 engines flagged this URL

We cross-check every URL against our antivirus network of 92 malware and blacklist engines. Each detection is listed below by engine name — even a single hit is a meaningful signal.

3Malicious2Suspicious55Harmless92Engines
0
of 92
ADMINUSLabs
Malicious· malicious
Chong Lua Dao
Malicious· malicious
Fortinet
Malicious· phishing
alphaMountain.ai
Suspicious· suspicious
Forcepoint ThreatSeeker
Suspicious· suspicious

5 antivirus engines flagged this URL. Even a single detection is a meaningful signal — treat this site with extra caution and avoid entering credentials, payment info, or downloading any files.

Security Scans

Blacklist Check
Not flagged on major threat lists

Checked against the major public blocklists used by browsers and security tools — no hits.

Sandbox Render
Sandbox capture incomplete — no traffic recorded
Requests made0
Unique IPs0
Countries0
Detected brandsNone

Domain & Encryption

Domain History
Age6 months old
RegistrarGoDaddy.com, LLC
RegisteredDec 6, 2025
ExpiresDec 6, 2026
Owner privacyVisible
Encryption Certificate
StatusValid
ProtocolTLSv1.2
IssuerLet's Encrypt · R12
ExpiresAug 9, 2026 (61d)
Self-signedNo
Hosting & Technology
HostingGoDaddy.com, LLC
Server locationUS

Server Reputation

Hosting
CountryUnknown
NetworkUnknown
IP addressUnknown
Abuse Intelligence
Confidence score0%
Reports on file0
ISPGoDaddy.com, LLC
Usage typeData Center/Web Hosting/Transit

Scam-Type Likelihood

3 scam-type patterns detected
Scam-Type Likelihood

3 of 13 categories showed signals

We check every URL against 13 distinct scam categories so the verdict tells you not just how risky the page is, but what kind of risk it carries. Each meter pulls from page signals, web reports, our AI analyst, vision, and the scam-network cluster — not from raw AV labels.

Top match: Brand Impersonation
Brand Impersonation
Moderate likelihood
30/100
  • AI analyst tagged this as a brand / clone-site impersonation.
  • Clustered with known brand-impersonation infrastructure.
Fake Shop
Low-level signals
25/100
  • AI analyst tagged this as a fake shop.
  • No phone number or postal address anywhere on the page.
Fake Giveaway
Low-level signals
12/100
  • AI analyst tagged this as a giveaway / airdrop / lottery scam.

Brand impersonation detected

This page is styled as a known brand but is not the brand's real site.

  • Do not interact with nyjfv.xyz

    Do not enter credentials, deposit money, download files, or install browser extensions from this site.

  • Go to the brand's real site directly

    Type the brand name into a search engine or open it from your bookmarks — don't use links from emails, SMS, ads, or social posts, which are the delivery vectors for impersonation.

  • Never download or sign in here

    Even if the page "just" offers a download or a giveaway, impersonation pages frequently deliver malware or set up follow-up phishing. Assume anything accepted from this site is hostile.

  • Report the impersonation to the brand

    Most major brands have a dedicated abuse or anti-phishing reporting channel — reporting helps them take the site down and protects other users.

    Open

Reputation Sources

How this domain rates across independent threat-intelligence and blocklist providers.

Google Safe Browsing
Not listedCheck ↗
VirusTotal
ListedCheck ↗
AbuseIPDB
Not listedCheck ↗

Safety FAQ

Common questions about this site, answered directly from the scan data above — so the answers always reflect the latest verdict on this page.

  • Our automated security review flags nyjfv.xyz as dangerous. Multiple threat indicators were detected — treat the site as a scam until proven otherwise.
  • No — nyjfv.xyz scored 1/100 on our trust scale. We detected active threat indicators, so we recommend avoiding the site entirely.
  • Yes. nyjfv.xyz presents a valid TLSv1.2 certificate issued by Let's Encrypt · R12, expiring in 61 days. Note that SSL only encrypts the connection — it does not guarantee that the site itself is trustworthy.
  • nyjfv.xyz is 6 months old, registered on 12/6/2025 through GoDaddy.com, LLC. Scam domains are often freshly registered — a site under 6 months old warrants extra caution.
  • 5 out of 92 antivirus engines in our malware network flagged nyjfv.xyz as malicious or suspicious (3 outright malicious). Even one detection is a meaningful signal.
  • No. nyjfv.xyz is not currently listed on the major browser blocklist feeds that modern browsers use.
  • nyjfv.xyz resolves to an IP operated by GoDaddy.com, LLC in US (usage type: Data Center/Web Hosting/Transit). Hosting location alone doesn't make a site good or bad, but unusual geography for a brand's claimed country is one of many signals we weigh.
  • We cache results for 24 hours. Signed-in MalwareTips members can trigger a manual rescan at any time using the "Rescan" button on the report page, which re-runs every check from scratch and refreshes this page.

Final Verdict

0
Trust / 100
Final Verdict·nyjfv.xyz
DANGEROUS

nyjfv.xyz is a confirmed clone of SHEIN designed to harvest credentials or payment data through fake promotional campaigns. Multiple antivirus engines flag it as malicious, and sandbox analysis confirms suspicious activity on promo-bait URLs.

Do not visit this site or enter any personal, payment, or credential information. If you encountered this domain via social media, report the post to the platform. If you have already entered credentials or payment data, contact your bank and payment provider immediately.

AV engines
92
MT passes
2
Net signals
2
Scan another URL
Security review completemalwaretips.com/url-scan
Recently scanned

Other Dangerous reports

Browse all reports
Community review

User reviews & comments(0)

Share your experience — "Lost $200 on a fake checkout" is more useful than "Scam". Your review helps others avoid traps.

Loading…
Loading comments…
This report is generated automatically by combining threat intelligence, domain signals, and an AI security analyst. It is informational, not legal advice. Always use your own judgement before sharing personal information or money online.