open-monex[.]guozhengjun[.]cn
“ログイン/マネックス証券”
open-monex.guozhengjun.cn — Não verificado. Resumo das evidências: VirusTotal 14/91 (BitDefender, CRDF, CyRadar, ESET, Forcepoint ThreatSeeker); Spamhaus DBL_SPAM; PhishDestroy score 92/100. Registrador: Web Commerce Communica….
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain open-monex.guozhengjun.cn was registered on August 31, 2023 through Web Commerce Communications Limited and is currently taken offline. Network analysis shows the domain resolves to the IPv6 address 2a06:98c1:3120::3, which belongs to AS13335 Cloudflare, Inc., placing the hosting infrastructure in the United States. No TLS certificate is presented, indicating the site was served without HTTPS encryption. The page title returned by the server is ログイン/マネックス証券, which translates to "Login / Monex Securities," suggesting an attempt to lure victims into credential harvesting for the Monex financial service.
Gridinsoft assigns a trust score of 0 out of 100, reflecting an extremely low confidence in the domain’s legitimacy. Detection services have flagged the domain; fifteen of ninety‑five VirusTotal scanners reported malicious behavior, and the domain is listed on at least one external security blocklist. PhishDestroy has also recorded the site as blocked. Nameservers harley.ns.cloudflare.com and mariah.ns.cloudflare.com confirm reliance on Cloudflare DNS.
While the site is offline, the observed indicators—hosted on a Cloudflare edge, lacking TLS, low trust score, malicious detection count, and a brand‑specific login title—are consistent with a generic phishing operation targeting Monex customers. Defenders should continue to block the domain at perimeter filters, monitor for any re‑activation, and update any URL‑based threat intelligence feeds with the observed IPv6 address and associated hostnames. Further analysis of any future HTTP responses or TLS certificates is required to confirm the presence of credential‑stealing pages if the domain reappears.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo