wjla-tiwaitlf-tiwaitlf-wjla[.]jindunqst[.]com
“域名停靠”
wjla-tiwaitlf-tiwaitlf-wjla.jindunqst.com — 未验证. 证据摘要: VirusTotal 15/91 (ADMINUSLabs, BitDefender, CRDF, CyRadar, ESET); CF Radar malicious; PhishDestroy score 95/100. 注册商: Gname.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain wjla-tiwaitlf-tiwaitlf-wjla.jindunqst.com was created on 24 September 2024 through the registrar Gname.com Pte. Ltd. and is delegated to the Alibaba Cloud DNS servers jm1.alidns.com and jm2.alidns.com. DNS resolution points to the IPv4 address 103.75.15.107, which belongs to AS132839 POWER LINE DATACENTER and is geolocated in Hong Kong. The site does not present an SSL/TLS certificate, meaning it is only reachable over HTTP. The single page that was observed returns the title “域名停靠”, which provides no indication of the intended victim target or malicious functionality. Security monitoring has placed the domain on one blocklist and it is actively blocked by the PhishDestroy service.
Reputation scoring from Gridinsoft rates the domain at 0 out of 100, indicating a complete lack of trust. VirusTotal analysis shows that 15 of 95 scanned security vendors flagged the domain as malicious, reinforcing the suspicion of phishing activity. The domain is currently reported as offline, and no further HTTP response details are available. Based on the available evidence, the infrastructure appears to be a typical short‑lived phishing host that relies on a low‑reputation DNS configuration, a non‑TLS web server, and a Hong Kong‑based hosting provider.
The precise phishing payload, target brand, or credential‑stealing technique has not been observed, leaving the exact attack vector unknown. Defenders should immediately add 103.75.15.107 to network deny lists, enforce blocking of the fully qualified domain name at DNS and proxy layers, and monitor for additional domains that resolve to the same IP or use the same nameservers. Continuous re‑scanning of the domain through multi‑vendor services such as VirusTotal is recommended in case the offline status changes.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
Registration: jindunqst.com
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For the registrable domain jindunqst.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。