www3-vpass[.]ynqbe[.]cn
“【重要】メンテナンスのお知らせ|VJAグループ Vpass”
www3-vpass.ynqbe.cn — Contenido no disponible (HTTP 502). Resumen de las pruebas: VirusTotal 19/95 (Criminal IP, alphaMountain.ai, BitDefender, CyRadar, Dr.Web); PhishDestroy score 95/100. Registrador: 长沙小豆网络科技有限公司.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain is flagged as an elevated-risk phishing site specifically designed to impersonate the VJA Group Vpass service, a Japanese credit card authentication platform. Analysis indicates the threat type is brand impersonation, targeting users with a fake maintenance notice to harvest login credentials. The page title, 「重要】メンテナンスのお知らせ|VJAグループ Vpass, mimics official VJA communications, increasing the likelihood of successful deception among Japanese-speaking users. Infrastructure analysis reveals multiple high-confidence threat indicators. The domain resolves to IP address 172.67.203.131, hosted on Cloudflare infrastructure (AS13335) in the United States, despite the Japanese-language content. Security vendors on VirusTotal flagged the domain with 19 detections out of 95 engines, a ratio that strongly suggests malicious intent. The domain was registered on May 24, 2025, through 长沙小豆网络科技有限公司, a registrar frequently associated with phishing domains. It appears on two security blocklists and is explicitly blocked by PhishDestroy and PhishingDB. Notably, the site lacks an SSL certificate, a red flag for any credential collection page, and is currently offline, likely due to takedown efforts. Users who may have interacted with this domain should take immediate mitigation steps. First, reset any credentials entered on the site, particularly Vpass, credit card, or banking logins, as these are the primary targets of this impersonation campaign. Enable multi-factor authentication on all financial and email accounts to prevent unauthorized access. Monitor financial statements for unauthorized transactions, as stolen credentials are often monetized quickly. Organizations should update security blocklists to include this domain and its associated IP address (172.67.203.131) to prevent future access attempts. Given the use of Cloudflare infrastructure, network administrators should also monitor for other domains resolving to the same IP range, as threat actors frequently reuse hosting providers for multiple campaigns.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.