hengyitong[.]com[.]cn
“°å½ð¼ôµ¶_ÈÕ±¾¹¤¾ß_ÈÕ±¾É豸_îÓ½ð¼ô_°å½ð»úеÉ豸_ÑÐÄ¥»úе - ºãÒæÍ¨¿Æ¼¼£¨ÉîÛÚ£©ÓÐÏÞ¹«Ë¾”
hengyitong.com.cn — Doğrulanmamış. Dolandırıcılık türü: Credential Phishing. Kanıt özeti: VirusTotal 15/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25); URLQuery 2 alerts; PhishDestroy score 95/100. Kayıt kuruluşu: 北京新网数码信息技术有限公司.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain, hengyitong.com.cn, operates as a credential harvesting portal designed to mimic legitimate corporate login pages. Analysis indicates the site employs form-based phishing techniques to capture usernames, passwords, and potentially multi-factor authentication tokens. The infrastructure is optimized for rapid deployment and evasion, with no SSL certificate to avoid certificate transparency logs and reduce detection likelihood. The site's design suggests targeting of enterprise users, likely through spear-phishing campaigns distributing direct links to the domain. Infrastructure analysis reveals multiple high-confidence indicators of malicious activity. The domain resolves to IP address 64.32.8.173, hosted on a provider known for bulletproof hosting services. VirusTotal detection rates show 14 out of 95 security vendors flagging the domain as malicious, with specific classifications including phishing and credential theft. The domain was registered on May 22, 2026, through a Chinese registrar, with the creation date potentially manipulated to appear legitimate. The domain appears on one security blocklist, specifically PhishDestroy, and is currently offline, suggesting either takedown or operational pause. Users who visited hengyitong.com.cn should immediately reset credentials for any accounts accessed through the site, particularly corporate or email accounts. Enable multi-factor authentication on all critical services and monitor accounts for unauthorized access attempts. Organizations should block the domain and IP address 64.32.8.173 at the network perimeter. Security teams should analyze endpoint logs for connections to the domain and IP, checking for successful credential submissions. Given the elevated risk level, affected users should consider password manager audits and credit monitoring if financial information was exposed.
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | hengyitong.com.cn |
malicious | Sinkholed |
| DNS4EU | hengyitong.com.cn |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin