vpass-jp[.]rbegd[.]cn
“【重要】メンテナンスのお知らせ|VJAグループ Vpass”
vpass-jp.rbegd.cn — 内容不可用 (HTTP 502). 证据摘要: VirusTotal 18/95 (ADMINUSLabs, Criminal IP, BitDefender, CyRadar, ESET); PhishDestroy score 95/100. 注册商: 商中在线科技股份有限公司.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Domain vpass-jp.rbegd.cn is assessed as a generic_phishing endpoint impersonating VJA Group Vpass authentication services. The infrastructure and page title indicate a credential harvesting attempt mimicking maintenance notification content. The domain is currently offline, reducing active exposure but not eliminating residual risk due to prior distribution.
Telemetry and external intelligence show the domain was flagged by 18 of 95 VirusTotal security vendors. Registration records indicate it was registered through 商中在线科技股份有限公司. Network resolution points to IP 172.67.204.113, hosted within AS13335 Cloudflare, Inc., with geolocation attributed to the United States. Domain creation date is recorded as May 17, 2025. Additional indicators include absence of a valid SSL certificate and presence on 2 known security blocklists, specifically PhishDestroy and PhishingDB. The same IP endpoint resolves directly to the observed host, suggesting centralized hosting infrastructure.
At present, the domain status is taken offline, which indicates mitigation actions by hosting providers or blocklisting entities. However, historical evidence suggests it was actively used for credential phishing, likely targeting VJA Vpass users. Security teams should maintain blocklist enforcement, monitor for re-registration under similar naming patterns, and implement DNS/IP-based filtering for 172.67.204.113 if correlated malicious activity persists. Users should be warned not to enter credentials on any pages referencing Vpass maintenance notices unless verified through official channels. Continued monitoring of certificate issuance attempts and domain resurrection under rbegd.cn subdomains is recommended.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。