sapporo-chugokugo[.]club
“札幌中国語クラブ”
sapporo-chugokugo.club — Nicht bestätigt. Markenidentität: 1and1ionos; Betrugstyp: Impersonation. Zusammenfassung der Beweislage: VirusTotal 14/91 (alphaMountain.ai, Cluster25, CRDF, ESET, Forcepoint ThreatSeeker); URLScan malicious verdict; PhishDestroy score 92/100.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Analysis as of August 05, 2026 indicates that the domain sapporo-chugokugo.club is actively being used in a generic phishing campaign. The domain resolves to the IPv4 address 163.44.185.225 and is hosted on name servers uns01.lolipop.jp and uns02.lolipop.jp, both belonging to the Lolipop hosting service. VirusTotal has recorded detections from eight of ninety‑one scanned security vendors, confirming that multiple AV engines identify malicious behavior associated with the domain. Independent phishing intelligence feeds have also flagged the domain: PhishDestroy and OpenPhish list it as blocked, and it appears on two additional security blocklists.
The domain’s current status remains active, meaning it continues to resolve and respond to queries. No public information was found regarding SSL certificate details, HTTP response codes, or page title content, so the exact appearance of the landing page cannot be confirmed at this time. The lack of additional infrastructure signals such as CDN usage or anomalous ASN activity suggests a relatively simple hosting setup typical of many low‑cost phishing operations. Defenders should treat connections to 163.44.185.225 originating from internal hosts as suspicious and consider enforcing network‑level deny rules for the domain and its IP address.
Updating DNS filtering solutions to include the domain and its associated name servers will help prevent resolution. Security products that ingest blocklist feeds should be verified to contain the domain, ensuring that PhishDestroy and OpenPhish entries are applied. Continuous monitoring of outbound traffic for HTTP/S requests to the domain is recommended, and any successful login attempts or credential submissions observed should be investigated as potential compromise events.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Abgleich mit Bedrohungsdaten · source references
Technologien · 4 identified
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. Features include a plugin architecture and a template system.
wordpress.org 100 % KonfidenzApache is a free and open-source cross-platform web server software.
httpd.apache.org 100 % KonfidenzVirusTotal-Analyse
Archivierte Beweise
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt