monex-co-jp[.]shanmao97[.]cn
“monex-co-jp.shanmao97.cn”
monex-co-jp.shanmao97.cn — Contenido no disponible (HTTP 502). Resumen de las pruebas: VirusTotal 16/93 (ADMINUSLabs, BitDefender, CyRadar, ESET, Forcepoint ThreatSeeker); Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 95/100. Registrador: Web Commerce Communica….
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of the domain monex-co-jp.shanmao97.cn indicates that it is currently offline but retains multiple indicators of malicious activity. VirusTotal records show that 16 of 93 security vendors have flagged the domain, suggesting a consensus of concern among scanning engines. Google Safe Browsing classifies the site as a social engineering threat, reinforcing the phishing characterization. The domain is actively blocked by the PhishDestroy network and appears on at least one external security blocklist, providing additional defensive layers for organizations that subscribe to those feeds.
The site presents a self‑signed Let’s Encrypt certificate (issuer: Let’s Encrypt / E8), which does not guarantee legitimacy and is commonly used by malicious operators to obtain HTTPS without scrutiny. DNS resolution points to IP address 103.149.92.164, which maps to Hong Kong and is associated with AS401696, identified as CognetCloud Inc. The hosting infrastructure is therefore located in a region often leveraged for rapid deployment of disposable web services. Registration data shows the domain was created on 21 February 2026 through Web Commerce Communications Limited, and the authoritative nameservers are ns1.julydns.com and ns2.julydns.com, both of which are frequently observed in transient malicious campaigns. Gridinsoft assigns a trust score of 0 out of 100, indicating a complete lack of confidence in the site’s safety.
The page title returned by the web server matches the domain string itself, offering no additional context about the intended victim or lure. While the site is no longer reachable, the persistence of its indicators in blocklists and security vendor feeds means that residual threats may exist, especially if the infrastructure is re‑used under a different domain.
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.