monex-co-jp[.]shanmao97[.]cn
“monex-co-jp.shanmao97.cn”
monex-co-jp.shanmao97.cn — İçerik kullanılamıyor (HTTP 502). Kanıt özeti: VirusTotal 16/93 (ADMINUSLabs, BitDefender, CyRadar, ESET, Forcepoint ThreatSeeker); Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 95/100. Kayıt kuruluşu: Web Commerce Communica….
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Analysis of the domain monex-co-jp.shanmao97.cn indicates that it is currently offline but retains multiple indicators of malicious activity. VirusTotal records show that 16 of 93 security vendors have flagged the domain, suggesting a consensus of concern among scanning engines. Google Safe Browsing classifies the site as a social engineering threat, reinforcing the phishing characterization. The domain is actively blocked by the PhishDestroy network and appears on at least one external security blocklist, providing additional defensive layers for organizations that subscribe to those feeds.
The site presents a self‑signed Let’s Encrypt certificate (issuer: Let’s Encrypt / E8), which does not guarantee legitimacy and is commonly used by malicious operators to obtain HTTPS without scrutiny. DNS resolution points to IP address 103.149.92.164, which maps to Hong Kong and is associated with AS401696, identified as CognetCloud Inc. The hosting infrastructure is therefore located in a region often leveraged for rapid deployment of disposable web services. Registration data shows the domain was created on 21 February 2026 through Web Commerce Communications Limited, and the authoritative nameservers are ns1.julydns.com and ns2.julydns.com, both of which are frequently observed in transient malicious campaigns. Gridinsoft assigns a trust score of 0 out of 100, indicating a complete lack of confidence in the site’s safety.
The page title returned by the web server matches the domain string itself, offering no additional context about the intended victim or lure. While the site is no longer reachable, the persistence of its indicators in blocklists and security vendor feeds means that residual threats may exist, especially if the infrastructure is re‑used under a different domain.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin