open-monex[.]guozhengjun[.]cn
“ログイン/マネックス証券”
open-monex.guozhengjun.cn — Non vérifié. Résumé des preuves: VirusTotal 14/91 (BitDefender, CRDF, CyRadar, ESET, Forcepoint ThreatSeeker); Spamhaus DBL_SPAM; PhishDestroy score 92/100. Bureau d’enregistrement: Web Commerce Communica….
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
The domain open-monex.guozhengjun.cn was registered on August 31, 2023 through Web Commerce Communications Limited and is currently taken offline. Network analysis shows the domain resolves to the IPv6 address 2a06:98c1:3120::3, which belongs to AS13335 Cloudflare, Inc., placing the hosting infrastructure in the United States. No TLS certificate is presented, indicating the site was served without HTTPS encryption. The page title returned by the server is ログイン/マネックス証券, which translates to "Login / Monex Securities," suggesting an attempt to lure victims into credential harvesting for the Monex financial service.
Gridinsoft assigns a trust score of 0 out of 100, reflecting an extremely low confidence in the domain’s legitimacy. Detection services have flagged the domain; fifteen of ninety‑five VirusTotal scanners reported malicious behavior, and the domain is listed on at least one external security blocklist. PhishDestroy has also recorded the site as blocked. Nameservers harley.ns.cloudflare.com and mariah.ns.cloudflare.com confirm reliance on Cloudflare DNS.
While the site is offline, the observed indicators—hosted on a Cloudflare edge, lacking TLS, low trust score, malicious detection count, and a brand‑specific login title—are consistent with a generic phishing operation targeting Monex customers. Defenders should continue to block the domain at perimeter filters, monitor for any re‑activation, and update any URL‑based threat intelligence feeds with the observed IPv6 address and associated hostnames. Further analysis of any future HTTP responses or TLS certificates is required to confirm the presence of credential‑stealing pages if the domain reappears.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif