www3-vpass[.]godqo[.]cn
“godqo.cn | 502: Bad gateway”
www3-vpass.godqo.cn — Inhalt nicht verfügbar (HTTP 502). Zusammenfassung der Beweislage: VirusTotal 20/95 (ADMINUSLabs, Criminal IP, BitDefender, Chong Lua Dao, CyRadar); Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 95/100. Registrar: 商中在线科技股份有限公司.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
This domain, www3-vpass.godqo.cn, poses a high-risk phishing threat designed to mimic legitimate VPN authentication portals. Analysis indicates the site likely targets corporate or personal VPN users by presenting a fraudulent login interface to capture credentials, session tokens, or multi-factor authentication codes. The use of a subdomain (www3-vpass) suggests an attempt to impersonate a secure access gateway, a common tactic in credential harvesting campaigns targeting remote workers or enterprise networks. Infrastructure analysis reveals concrete indicators of malicious intent. The domain was registered on May 17, 2025, through 商中在线科技股份有限公司, a registrar frequently associated with short-lived phishing domains. It resolves to IP address 172.67.216.65, hosted on Cloudflare’s network (AS13335), which provides anonymity and complicates takedown efforts. Security vendors have flagged the domain 20 times out of 95 on VirusTotal, with Google Safe Browsing and two additional blocklists confirming its phishing classification. The SSL certificate, issued by TrustAsia Technologies, Inc., further masks its malicious nature by presenting a seemingly legitimate encrypted connection. Users who visited www3-vpass.godqo.cn should take immediate action to mitigate potential compromise. First, reset any credentials entered on the site, prioritizing passwords for VPNs, email accounts, or other sensitive services. Enable multi-factor authentication if not already active, and monitor accounts for unauthorized access or unusual activity. If corporate credentials were exposed, report the incident to internal security teams to initiate incident response protocols. Additionally, check local devices for malware or unauthorized software installations, as phishing sites often deploy secondary payloads. Block the domain and its associated IP (172.67.216.65) at the network level to prevent future access. Given the domain’s current offline status, users should remain vigilant for similar threats, particularly those mimicking VPN or remote access portals.
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
VirusTotal-Analyse
Archivierte Beweise
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of www3-vpass.godqo.cn · checked Mar 1, 2026
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt