vpass-jp[.]ohjgi[.]cn
“【重要】メンテナンスのお知らせ|VJAグループ Vpass”
vpass-jp.ohjgi.cn — 内容不可用 (HTTP 502). 证据摘要: VirusTotal 19/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); PhishDestroy score 95/100. 注册商: 长沙小豆网络科技有限公司.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain vpass-jp.ohjgi.cn has been identified as a generic phishing threat, specifically impersonating the VJA Group Vpass service to deceive users into believing they are visiting an official maintenance page. Currently, this domain is offline, but during its active period it posed a significant risk to individuals expecting legitimate communications from VJA.
Technical analysis reveals that this domain was created on May 24, 2025, and registered through 长沙小豆网络科技有限公司. It resolved to IP address 172.67.168.219 and lacked any SSL certificate, a critical red flag for any site requesting sensitive information. VirusTotal flagged the domain with 19 out of 95 security vendors, and it appeared on one security blocklist. These indicators, combined with the suspicious registration and lack of encryption, strongly suggest malicious intent aimed at credential harvesting or financial fraud.
Given that the domain is now taken offline, the immediate threat is neutralized. However, users who may have interacted with this site should change their Vpass passwords and monitor accounts for unauthorized activity. PhishDestroy recommends enabling multi-factor authentication where available and remaining vigilant against future phishing attempts that mimic trusted brands. Always verify website URLs and look for SSL certificates before entering personal information.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。