jojo[.]luxe
“Netflix”
Зведення доказів
This domain, jojo.luxe, is identified as a high-risk phishing site specifically designed to impersonate Netflix login pages. Analysis confirms it is actively harvesting user credentials through a fraudulent interface mimicking the official Netflix authentication portal. The threat type is classified as a fake login page under brand impersonation, targeting subscribers of the streaming service with the intent to steal account access and personal data. Infrastructure analysis reveals the domain was registered on August 13, 2025, through Alibaba Cloud Computing Ltd. d/b/a HiChina (www.net.cn). It currently resolves to the IP address 43.156.51.36, which has been flagged by 13 of 95 security vendors on VirusTotal. The page title explicitly displays 'Netflix,' reinforcing the deception. No additional blocklist entries or trust scores from other threat intelligence platforms were provided, but the detection ratio and recent registration strongly correlate with malicious intent. The domain remains active as of the latest verification. Organizations and individuals are advised to block access to jojo.luxe at the network level, update endpoint protection rules to include this domain and its associated IP, and alert users to avoid entering credentials on this site. Security teams should monitor for credential reuse attempts stemming from this campaign and consider initiating password reset protocols for potentially compromised accounts. Given the high-risk classification, immediate action is recommended to mitigate exposure.
Знімок надісланих доказів
- Надіслано
- Записи журналу
- 1
- ID справи
PD-20260703-4F611D- Заголовок збереженої сторінки
- Netflix
- PDF-файл
- PDF із доказами
Повний текст доказів
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (CN):
Cybersecurity Law of China
Criminal Law Article 285
Criminal Law Article 266 - Fraud
Chinese law strictly prohibits cyber fraud and illegal access to computer systems.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології
Виявлено 3 технології з високою впевненістю
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога