open-monex[.]morkr[.]cn
“ログイン/マネックス証券”
open-monex.morkr.cn — Konten tidak tersedia (HTTP 502). Ringkasan bukti: VirusTotal 17/95 (ADMINUSLabs, BitDefender, CyRadar, ESET, Forcepoint ThreatSeeker); PhishDestroy score 95/100. Registrar: Web Commerce Communica….
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
open-monex.morkr.cn is currently offline but historical data indicates it was used in a phishing campaign targeting users of Monex Securities. The page title observed during prior crawls was the Japanese phrase “ログイン/マネックス証券”, which directly references the login page of the Monex brokerage service, suggesting credential‑harvesting intent. Registration information shows the domain was created on 11 April 2024 through Web Commerce Communications Limited, and the authoritative nameservers are cleo.ns.cloudflare.com and rosalie.ns.cloudflare.com, both belonging to Cloudflare’s DNS service. DNS resolution points to IP address 104.21.31.246, which is owned by Cloudflare, Inc. (AS13335) and geolocated to the United States.
No SSL certificate was presented at the time of analysis, leaving the connection unencrypted and increasing the likelihood of man‑in‑the‑middle interception. Reputation checks reveal that the domain appears on one security blocklist and has been actively blocked by PhishDestroy. VirusTotal recorded 17 positive detections out of 95 scanned engines, indicating a moderate consensus among anti‑malware vendors that the domain is malicious. Gridinsoft assigned a trust score of 0 out of 100, reinforcing the assessment of high risk.
The absence of a valid TLS certificate, the low trust score, and the presence on blocklists collectively confirm the malicious nature of the infrastructure. Uncertainty remains regarding the current operational status of any backend phishing infrastructure, as the domain is listed as offline and no active HTTP response was captured. Defenders should continue to block the domain at perimeter filters, monitor DNS queries for the associated IP and nameservers, and incorporate the observed indicators—such as the page title, IP address, and detection counts—into threat‑intel feeds.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Analisis VirusTotal
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive