tonghedianzi[.]com
“PayPay公式 | 緊急セキュリティアップデート Ver.10.0 ダウンロード”
tonghedianzi.com — Conteúdo indisponível. Representação da marca: Google. Resumo das evidências: VirusTotal 8/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Fortinet, Google Safe Browsing); Google Safe Browsing flagged; PhishDestroy score 80/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
On August 02, 2026, analysis identified the domain tonghedianzi.com as an active generic phishing infrastructure with an elevated risk rating. The domain resolves to the IPv4 address 34.97.225.89, indicating a single hosting endpoint that is currently reachable. Reputation services have taken action: PhishDestroy has listed the domain as blocked, and Google Safe Browsing categorizes it under social engineering, which aligns with the generic phishing classification. VirusTotal scans show that eight of ninety‑one scanning engines return a malicious verdict, providing independent corroboration of the threat. Additionally, the domain appears on one external security blocklist, further confirming its inclusion in threat intelligence feeds.
The available intelligence does not disclose the registrar, SSL certificate details, HTTP response codes, or any page‑title metadata, leaving those aspects of the infrastructure unverified. Consequently, defenders cannot assess whether the site employs HTTPS, what content is served, or whether any redirection mechanisms are in place. Because the site’s landing page has not been publicly analyzed, analysts cannot confirm the exact phishing lure or credential collection method, and the threat may evolve to target additional brands. Given the confirmed detections and the active status, security teams should block network traffic to 34.97.225.89 and add tonghedianzi.com to local deny lists.
Monitoring of DNS queries for the domain is recommended to detect potential lateral propagation. Organizations employing email filters should ensure that messages containing URLs to this domain are quarantined or rejected. Defenders should also consider sharing any observed indicators of compromise with community blocklists to improve collective detection. Continuous re‑evaluation is advised, as additional detection signatures may emerge from further scanning or community reporting.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
Cruzamento de inteligência de ameaças · source references
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo