tonghedianzi[.]com
“PayPay公式 | 緊急セキュリティアップデート Ver.10.0 ダウンロード”
Evidence Summary
On August 02, 2026, analysis identified the domain tonghedianzi.com as an active generic phishing infrastructure with an elevated risk rating. The domain resolves to the IPv4 address 34.97.225.89, indicating a single hosting endpoint that is currently reachable. Reputation services have taken action: PhishDestroy has listed the domain as blocked, and Google Safe Browsing categorizes it under social engineering, which aligns with the generic phishing classification. VirusTotal scans show that eight of ninety‑one scanning engines return a malicious verdict, providing independent corroboration of the threat. Additionally, the domain appears on one external security blocklist, further confirming its inclusion in threat intelligence feeds.
The available intelligence does not disclose the registrar, SSL certificate details, HTTP response codes, or any page‑title metadata, leaving those aspects of the infrastructure unverified. Consequently, defenders cannot assess whether the site employs HTTPS, what content is served, or whether any redirection mechanisms are in place. Because the site’s landing page has not been publicly analyzed, analysts cannot confirm the exact phishing lure or credential collection method, and the threat may evolve to target additional brands. Given the confirmed detections and the active status, security teams should block network traffic to 34.97.225.89 and add tonghedianzi.com to local deny lists.
Monitoring of DNS queries for the domain is recommended to detect potential lateral propagation. Organizations employing email filters should ensure that messages containing URLs to this domain are quarantined or rejected. Defenders should also consider sharing any observed indicators of compromise with community blocklists to improve collective detection. Continuous re‑evaluation is advised, as additional detection signatures may emerge from further scanning or community reporting.
Data Coverage
Network Security Intelligence
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 11, 2026
10 monitored external feeds No match
Detection timeline
-
Google Safe Browsing
0 → 1
-
Domain status
Reachable → Unreachable
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive