qrtn[.]jp
Analyse phishing et sécurité de qrtn.jp
“QRouton|KADOKAWAのQRコード&短縮URL”
qrtn.jp — Dernier actif connu (HTTP 301). Résumé des preuves: VirusTotal 5/91 (alphaMountain.ai, Chong Lua Dao, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); URLQuery 2 alerts; 1 external blocklist match (ScamSniffer); PhishDestroy score 83/100.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis of qrtn.jp indicates a high-risk phishing domain targeting users through QR code and URL shortening services under the guise of KADOKAWA, a known Japanese media brand. The domain was registered on February 21, 2026, and remains active as of July 12, 2026. It resolves to IP 52.199.127.131 (AS16509, Amazon.com, Inc., located in Japan) and employs Cloudflare for hosting, alongside Amazon Web Services infrastructure. The page title explicitly references KADOKAWA's QR code and short URL service, suggesting an attempt to impersonate or misuse the brand's identity. Technical indicators reveal the domain is flagged by 2 security blocklists and appears in 2 AlienVault OTX threat intelligence pulses, reinforcing its malicious classification. One of 93 security vendors on VirusTotal has detected the domain as malicious, though the limited detection rate does not diminish its risk given corroborating evidence. The domain uses a 301 HTTP redirect, a common tactic to obscure final destinations or distribute malicious payloads. SSL certification is provided by Amazon RSA 2048 M02, a standard but not inherently trustworthy certificate authority in this context. Defenders should treat qrtn.jp as an active threat. Block the domain and its resolving IP at perimeter security controls. Monitor for connections to 52.199.127.131 or attempts to access the domain, particularly in environments where QR code or URL shortening services are utilized. The exact phishing mechanism remains unconfirmed due to lack of detailed page analysis, but the combination of brand impersonation, recent registration, and security vendor detections justifies immediate containment. No evidence suggests this domain is legitimate or safe for user interaction.
Renseignements sur la sécurité réseau
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | qrtn.jp |
malicious | Sinkholed |
| DNS4EU | qrtn.jp |
malicious | Sinkholed |
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 9 identified
Popular CSS framework for responsive, mobile-first web development.
Payment processor — credit card and alt-payment acceptance.
stripe.comCloud computing platform offering compute, storage, and networking services.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comFast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comWeb analytics service tracking website traffic and user behavior.
marketingplatform.google.comAnalyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of qrtn.jp · checked Mar 2, 2026
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif