jifen[.]ule[.]com
Analyse phishing et sécurité de jifen.ule.com
“中国邮政积分商城”
jifen.ule.com — Masqué · accessible (HTTP 200). Résumé des preuves: VirusTotal 1/91 (Gridinsoft); 1 external blocklist match (ScamSniffer); cloaking observed; PhishDestroy score 86/100. Bureau d’enregistrement: Alibaba Cloud Computing.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Evidence Analysis
The domain jifen.ule.com was a generic phishing site that posed an elevated risk of credential theft or financial fraud. It did not impersonate a specific brand but displayed the page title '中国邮政积分商城', which may have misled users into believing it was associated with a legitimate rewards program. No crypto drainer kit was identified. The site is currently taken offline, reducing immediate risk to visitors.
Technical analysis shows jifen.ule.com was flagged by 2 of 95 VirusTotal security vendors, including G-Data and Gridinsoft, which assigned a trust score of 0/100. It appeared on 2 security blocklists (PhishDestroy and ScamSniffer) but was not flagged by Google Safe Browsing. The domain was registered through Alibaba Cloud Computing Ltd. d/b/a HiChina (www.net.cn) on September 10, 1998, and resolved to the IP address 36.110.230.112, located in China (AS23724). The SSL certificate was issued by GlobalSign nv-sa / GlobalSign RSA OV SSL CA 2018. Detected technologies included Nginx, OpenResty, jQuery, and HSTS. Nameservers were ns3.dnsv5.com and ns4.dnsv5.com.
Users who visited jifen.ule.com should assume their credentials may have been compromised. Change passwords for any accounts accessed after visiting the site, enable two-factor authentication (2FA) where available, and monitor accounts for unauthorized activity. Report the domain to local cybersecurity authorities or platforms like Google Safe Browsing, PhishTank, or the Anti-Phishing Working Group (APWG) to aid in broader threat mitigation.
Couverture des données12 recorded checks
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
ICANN OVERSIGHT
Registration: ule.com
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain ule.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 4 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Web platform based on Nginx with LuaJIT for scalable web apps.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Analyse VirusTotal
Preuves archivées
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of jifen.ule.com · checked Mar 2, 2026
Données factuelles et rapports externesIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.