vpass-jp[.]tuqln[.]cn
“【重要】メンテナンスのお知らせ|VJAグループ Vpass”
vpass-jp.tuqln.cn — İçerik kullanılamıyor (HTTP 502). Kanıt özeti: VirusTotal 18/95 (ADMINUSLabs, BitDefender, Chong Lua Dao, CyRadar, ESET); PhishDestroy score 95/100. Kayıt kuruluşu: 商中在线科技股份有限公司.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain, vpass-jp.tuqln.cn, presents an elevated-risk credential theft operation targeting users of the VJA Vpass service. The site displays a fraudulent maintenance notice in Japanese, titled 「重要】メンテナンスのお知らせ|VJAグループ Vpass, designed to harvest login credentials by mimicking the legitimate Vpass platform. Analysis indicates the page employs no SSL encryption, increasing exposure of sensitive data during transmission. The threat specifically exploits trust in the VJA brand, a common target for credential theft due to its association with financial and personal identification services in Japan. Infrastructure analysis reveals the domain was registered on May 17, 2025, through 商中在线科技股份有限公司, a registrar frequently associated with malicious domains. The domain resolves to IP address 172.67.130.37, hosted on AS13335 Cloudflare, Inc., a network often leveraged to obscure the true origin of phishing infrastructure. Detection metrics further substantiate the threat: 18 out of 95 security vendors on VirusTotal flag this domain as malicious, and it appears on at least one security blocklist, including PhishDestroy. The absence of SSL certification and the use of Cloudflare IP space are consistent with credential theft campaigns seeking to evade detection while maximizing reach. Users who visited vpass-jp.tuqln.cn should immediately take corrective action to mitigate risk. First, revoke any credentials entered on the site, particularly those associated with VJA Vpass or other financial services. Enable multi-factor authentication on all critical accounts to prevent unauthorized access. Monitor linked financial accounts and credit reports for suspicious activity, as stolen credentials may be used for fraudulent transactions or identity theft. Report the incident to relevant authorities or the legitimate VJA Vpass support team to assist in broader mitigation efforts. Avoid interacting with any communications claiming to be from VJA or Vpass that reference unexpected maintenance or account issues, as these may be follow-up phishing attempts.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin