vpass-jp[.]rbegd[.]cn
“【重要】メンテナンスのお知らせ|VJAグループ Vpass”
vpass-jp.rbegd.cn — Контент недоступний (HTTP 502). Зведення доказів: VirusTotal 18/95 (ADMINUSLabs, Criminal IP, BitDefender, CyRadar, ESET); PhishDestroy score 95/100. Реєстратор: 商中在线科技股份有限公司.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Domain vpass-jp.rbegd.cn is assessed as a generic_phishing endpoint impersonating VJA Group Vpass authentication services. The infrastructure and page title indicate a credential harvesting attempt mimicking maintenance notification content. The domain is currently offline, reducing active exposure but not eliminating residual risk due to prior distribution.
Telemetry and external intelligence show the domain was flagged by 18 of 95 VirusTotal security vendors. Registration records indicate it was registered through 商中在线科技股份有限公司. Network resolution points to IP 172.67.204.113, hosted within AS13335 Cloudflare, Inc., with geolocation attributed to the United States. Domain creation date is recorded as May 17, 2025. Additional indicators include absence of a valid SSL certificate and presence on 2 known security blocklists, specifically PhishDestroy and PhishingDB. The same IP endpoint resolves directly to the observed host, suggesting centralized hosting infrastructure.
At present, the domain status is taken offline, which indicates mitigation actions by hosting providers or blocklisting entities. However, historical evidence suggests it was actively used for credential phishing, likely targeting VJA Vpass users. Security teams should maintain blocklist enforcement, monitor for re-registration under similar naming patterns, and implement DNS/IP-based filtering for 172.67.204.113 if correlated malicious activity persists. Users should be warned not to enter credentials on any pages referencing Vpass maintenance notices unless verified through official channels. Continued monitoring of certificate issuance attempts and domain resurrection under rbegd.cn subdomains is recommended.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога