3-ouyi-app[.]com[.]cn
“欧易官方网址下载- KYC认证全流程指南:安卓与电脑端安装图文教程”
3-ouyi-app.com.cn — 未验证. 证据摘要: VirusTotal 12/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, ESET, Forcepoint ThreatSeeker); CF Radar malicious; PhishDestroy score 88/100. 注册商: 四川域趣网络科技有限公司.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of the domain 3-ouyi-app.com.cn, created on 21 February 2026 and registered through 四川域趣网络科技有限公司, shows a high‑risk generic phishing infrastructure that remains active as of 23 July 2026. The authoritative name servers ns3.myhostadmin.net and ns4.myhostadmin.net resolve the domain to IP 45.194.153.167, an address assigned to AS134548 (DXTL Tseung Kwan O Service) located in Hong Kong. The site presents a valid TLS certificate issued by Let’s Encrypt (R13) and serves content over HTTP/3 with HSTS enabled. An HTTP GET returns status 200 and the page title is “欧易官方网址下载- KYC认证全流程指南:安卓与电脑端安装图文教程”, indicating a focus on KYC certification instructions. Underlying technologies include WordPress, MySQL, PHP, Nginx, and jQuery, suggesting a typical content‑management stack.
Security assessments show a Gridinsoft trust score of 0 out of 100, confirming the site is deemed untrustworthy by that engine. VirusTotal analysis reports that 15 of 93 scanning engines flagged the domain, and the domain appears on one external blocklist and is specifically listed by PhishDestroy. No additional public blocklist entries or Safe Browsing alerts are referenced. The combination of a recent registration, low trust score, multiple vendor detections, and active blocklist listings points to a purposeful phishing campaign targeting users seeking KYC verification for an apparently Chinese service.
Uncertainty remains regarding the exact payload or credential‑harvesting mechanisms, as the page content has not been examined directly. Defenders should block the domain at perimeter firewalls, add it to DNS sinkhole lists, and monitor outbound connections to the hosting IP. Incident response teams should treat any credential submissions to this domain as compromised, enforce password resets for affected accounts, and consider sharing indicators of compromise with threat‑sharing platforms.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 7 identified
Open-source CMS powering over 40% of websites worldwide.
Open-source relational database management system.
Server-side scripting language designed for web development.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of 3-ouyi-app.com.cn · checked Mar 2, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。