Analysis of the domain j75e.vip indicates that it is currently active and associated with a high‑risk generic phishing campaign. The domain resolves to the IP address 103.244.148.114 and is served by four authoritative name servers: ns1.1111343.com, ns2.1111343.com, ns3.1111343.com, and ns4.1111343.com. Threat intelligence feeds have placed j75e.vip on at least one security blocklist, and it is explicitly blocked by the PhishDestroy filtering service, confirming its presence on known anti‑phishing infrastructure lists.
VirusTotal scans show that eight of ninety‑one participating security vendors have flagged the domain as malicious, providing independent corroboration of its suspicious nature. No public evidence has been released regarding the domain’s registrar, SSL certificate details, HTTP response codes, Safe Browsing status, OTX mentions, or page title, and no additional analysis links are presently available. Given the convergence of active DNS resolution, confirmed blocklist inclusion, and multi‑vendor detection, defensive operators should treat j75e.vip as a malicious phishing resource.
Recommended mitigation steps include adding the domain and its resolved IP address to outbound filtering rules, updating intrusion detection signatures to block traffic to the listed name servers, and monitoring network logs for any connections to 103.244.148.114. Continuous re‑evaluation is advised, as the threat landscape may evolve and further indicators could emerge.