monex-co-jp[.]0793sjpc[.]cn
“ログイン/マネックス証券”
monex-co-jp.0793sjpc.cn — Неперевірений. Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 17/91 (ADMINUSLabs, BitDefender, Chong Lua Dao, CRDF, CyRadar); PhishDestroy score 95/100. Реєстратор: Web Commerce Communica….
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain monex-co-jp.0793sjpc.cn has been identified as a credential harvesting phishing site specifically designed to impersonate Monex Securities, a legitimate financial services provider. Analysis confirms the site was operational with the page title ログイン/マネックス証券, directly mimicking the authentic login portal of the targeted brand. Current status indicates the domain has been taken offline, though prior activity remains a significant concern for users who may have interacted with the fraudulent page. Infrastructure analysis reveals multiple high-confidence indicators of malicious activity. The domain was registered through Web Commerce Communications Limited and has been flagged by 17 of 95 security vendors on VirusTotal, including entries on two distinct security blocklists. No SSL certificate was present, increasing the risk of credential interception during transmission. The domain was created on August 25, 2023, and resolves to the IPv6 address 2606:4700:3031::ac43:b610, hosted on AS13335 Cloudflare, Inc. infrastructure. The use of Cloudflare services is consistent with threat actor tactics to obfuscate origin servers and evade detection. The elevated risk level assigned to this domain is justified by the combination of brand impersonation, absence of encryption, and confirmed malicious detections. While the site is currently offline, affected users should immediately reset credentials for Monex Securities and any other accounts where identical login details may have been reused. Organizations are advised to block the domain at the network perimeter and monitor for related indicators of compromise, including the IPv6 address and registrar details. Proactive measures such as multi-factor authentication and user education on recognizing phishing attempts are strongly recommended to mitigate future exposure.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога