aiysha[.]jp
“403 Forbidden”
aiysha.jp — 未验证. 诈骗类型:Crypto Drainer. 证据摘要: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); PhishDestroy score 71/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Domain aiysha.jp is currently hosting a generic phishing campaign identified as a crypto drainer designed to steal cryptocurrency funds through fake login pages. No specific brand impersonation has been confirmed at this stage, but the campaign follows typical drainer kit behavior, including obfuscated JavaScript payloads and automated fund transfer mechanisms. The domain leverages social engineering to trick users into connecting their wallets or entering credentials, which are then exfiltrated to attacker-controlled addresses. This domain was registered on March 17, 2016, and is currently resolving to IP address 112.78.112.34. According to VirusTotal analysis dated from seed 4a76d7, the domain has 0 detections out of 95 scans, indicating it remains under the radar of most security vendors. The domain uses a valid SSL certificate issued by Let's Encrypt, likely to enhance credibility and bypass browser security warnings. As of the latest scan, no blocklist entries were recorded, and Google Safe Browsing (GSB) status remains unflagged. The registrar is not specified in the available data, but the domain's age and low detection rate suggest a deliberate strategy to avoid early detection. The campaign is classified as active and under investigation, with a current risk level of under_investigation. PhishDestroy has flagged this domain via seed 4a76d7 and is actively monitoring for infrastructure changes or expanded targeting. Immediate action is recommended: users are advised to avoid interacting with aiysha.jp and to verify any suspicious links using PhishDestroy's real-time scanning tool. While no confirmed incidents of fund loss have been reported yet, the combination of low detection, valid SSL, and drainer-style behavior indicates a significant risk of fraudulent activity. Remain vigilant and report any wallet connections or login prompts originating from this domain.
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 置信度 100%VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。