www3-vpass[.]ynqbe[.]cn
“【重要】メンテナンスのお知らせ|VJAグループ Vpass”
www3-vpass.ynqbe.cn — Контент недоступен (HTTP 502). Сводка доказательств: VirusTotal 19/95 (Criminal IP, alphaMountain.ai, BitDefender, CyRadar, Dr.Web); PhishDestroy score 95/100. Регистратор: 长沙小豆网络科技有限公司.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain is flagged as an elevated-risk phishing site specifically designed to impersonate the VJA Group Vpass service, a Japanese credit card authentication platform. Analysis indicates the threat type is brand impersonation, targeting users with a fake maintenance notice to harvest login credentials. The page title, 「重要】メンテナンスのお知らせ|VJAグループ Vpass, mimics official VJA communications, increasing the likelihood of successful deception among Japanese-speaking users. Infrastructure analysis reveals multiple high-confidence threat indicators. The domain resolves to IP address 172.67.203.131, hosted on Cloudflare infrastructure (AS13335) in the United States, despite the Japanese-language content. Security vendors on VirusTotal flagged the domain with 19 detections out of 95 engines, a ratio that strongly suggests malicious intent. The domain was registered on May 24, 2025, through 长沙小豆网络科技有限公司, a registrar frequently associated with phishing domains. It appears on two security blocklists and is explicitly blocked by PhishDestroy and PhishingDB. Notably, the site lacks an SSL certificate, a red flag for any credential collection page, and is currently offline, likely due to takedown efforts. Users who may have interacted with this domain should take immediate mitigation steps. First, reset any credentials entered on the site, particularly Vpass, credit card, or banking logins, as these are the primary targets of this impersonation campaign. Enable multi-factor authentication on all financial and email accounts to prevent unauthorized access. Monitor financial statements for unauthorized transactions, as stolen credentials are often monetized quickly. Organizations should update security blocklists to include this domain and its associated IP address (172.67.203.131) to prevent future access attempts. Given the use of Cloudflare infrastructure, network administrators should also monitor for other domains resolving to the same IP range, as threat actors frequently reuse hosting providers for multiple campaigns.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание