monex-co-jp[.]shanmao97[.]cn
“monex-co-jp.shanmao97.cn”
monex-co-jp.shanmao97.cn — المحتوى غير متوفر (HTTP 502). ملخص الأدلة: VirusTotal 16/93 (ADMINUSLabs, BitDefender, CyRadar, ESET, Forcepoint ThreatSeeker); Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 95/100. مسجّل النطاق: Web Commerce Communica….
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of the domain monex-co-jp.shanmao97.cn indicates that it is currently offline but retains multiple indicators of malicious activity. VirusTotal records show that 16 of 93 security vendors have flagged the domain, suggesting a consensus of concern among scanning engines. Google Safe Browsing classifies the site as a social engineering threat, reinforcing the phishing characterization. The domain is actively blocked by the PhishDestroy network and appears on at least one external security blocklist, providing additional defensive layers for organizations that subscribe to those feeds.
The site presents a self‑signed Let’s Encrypt certificate (issuer: Let’s Encrypt / E8), which does not guarantee legitimacy and is commonly used by malicious operators to obtain HTTPS without scrutiny. DNS resolution points to IP address 103.149.92.164, which maps to Hong Kong and is associated with AS401696, identified as CognetCloud Inc. The hosting infrastructure is therefore located in a region often leveraged for rapid deployment of disposable web services. Registration data shows the domain was created on 21 February 2026 through Web Commerce Communications Limited, and the authoritative nameservers are ns1.julydns.com and ns2.julydns.com, both of which are frequently observed in transient malicious campaigns. Gridinsoft assigns a trust score of 0 out of 100, indicating a complete lack of confidence in the site’s safety.
The page title returned by the web server matches the domain string itself, offering no additional context about the intended victim or lure. While the site is no longer reachable, the persistence of its indicators in blocklists and security vendor feeds means that residual threats may exist, especially if the infrastructure is re‑used under a different domain.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب