abpayqianbaoappguanfangxiazaigw[.]com[.]cn
“ABPAY钱包APP官方下载 - 一站式数字钱包支付平台”
Analysis indicates that the domain abpayqianbaoappguanfangxiazaigw.com.cn was registered on 23 May 2026 and currently resolves to the IPv4 address 154.194.137.70, which is geolocated to Hong Kong and associated with Starbow Ltd. The host presents a valid TLS certificate issued by Let’s Encrypt (identifier YE1) and serves HTTP 200 responses over an Nginx stack that includes Bootstrap and enforces HSTS. The page title returned by the server reads “ABPAY钱包APP官方下载 - 一站式数字钱包支付平台”, suggesting an attempt to masquerade as an official digital‑wallet application download page. The domain is classified as generic_phishing with a high risk rating and is listed as active. It has been blocked by the PhishDestroy blocklist and appears on one additional security blocklist. Reputation scoring from Gridinsoft rates the site at 0/100, and AlienVault OTX references the domain in a single threat pulse. VirusTotal analysis shows that 16 of 91 scanning engines flagged the host as malicious, reinforcing the phishing assessment. Uncertainty remains regarding the specific payload or credential‑harvesting mechanisms employed, as no detailed content inspection has been shared. Defenders should treat any traffic to this host as hostile. Recommended mitigations include adding the domain and its resolving IP to deny‑list rules on perimeter firewalls, DNS filtering, and endpoint protection suites, monitoring for anomalous outbound connections to the IP, and ensuring users are educated about unsolicited prompts to download or install the ABPAY wallet application. Continuous re‑evaluation is advised as further indicators may emerge.
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | abpayqianbaoappguanfangxiazaigw.com.cn |
malicious | Sinkholed |
| OpenDNS | abpayqianbaoappguanfangxiazaigw.com.cn |
phishing | Phishing Block |
| DNS4EU | abpayqianbaoappguanfangxiazaigw.com.cn |
malicious | Sinkholed |
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
Technologies · 3 identified
Bootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
getbootstrap.com 100% confidenceNginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% confidenceHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% confidenceVirusTotal Analysis
Site Configuration Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive