hengyitong[.]com[.]cn
“°å½ð¼ôµ¶_ÈÕ±¾¹¤¾ß_ÈÕ±¾É豸_îÓ½ð¼ô_°å½ð»úеÉ豸_ÑÐÄ¥»úе - ºãÒæÍ¨¿Æ¼¼£¨ÉîÛÚ£©ÓÐÏÞ¹«Ë¾”
hengyitong.com.cn — لم يتم التحقق منها. نوع الاحتيال: Credential Phishing. ملخص الأدلة: VirusTotal 15/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25); URLQuery 2 alerts; PhishDestroy score 95/100. مسجّل النطاق: 北京新网数码信息技术有限公司.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
This domain, hengyitong.com.cn, operates as a credential harvesting portal designed to mimic legitimate corporate login pages. Analysis indicates the site employs form-based phishing techniques to capture usernames, passwords, and potentially multi-factor authentication tokens. The infrastructure is optimized for rapid deployment and evasion, with no SSL certificate to avoid certificate transparency logs and reduce detection likelihood. The site's design suggests targeting of enterprise users, likely through spear-phishing campaigns distributing direct links to the domain. Infrastructure analysis reveals multiple high-confidence indicators of malicious activity. The domain resolves to IP address 64.32.8.173, hosted on a provider known for bulletproof hosting services. VirusTotal detection rates show 14 out of 95 security vendors flagging the domain as malicious, with specific classifications including phishing and credential theft. The domain was registered on May 22, 2026, through a Chinese registrar, with the creation date potentially manipulated to appear legitimate. The domain appears on one security blocklist, specifically PhishDestroy, and is currently offline, suggesting either takedown or operational pause. Users who visited hengyitong.com.cn should immediately reset credentials for any accounts accessed through the site, particularly corporate or email accounts. Enable multi-factor authentication on all critical services and monitor accounts for unauthorized access attempts. Organizations should block the domain and IP address 64.32.8.173 at the network perimeter. Security teams should analyze endpoint logs for connections to the domain and IP, checking for successful credential submissions. Given the elevated risk level, affected users should consider password manager audits and credit monitoring if financial information was exposed.
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | hengyitong.com.cn |
malicious | Sinkholed |
| DNS4EU | hengyitong.com.cn |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب