www3-vpass[.]kbqrc[.]cn
“【重要】メンテナンスのお知らせ|VJAグループ Vpass”
www3-vpass.kbqrc.cn — 内容不可用 (HTTP 502). 证据摘要: VirusTotal 18/95 (ADMINUSLabs, Criminal IP, BitDefender, CyRadar, ESET); PhishDestroy score 95/100. 注册商: 商中在线科技股份有限公司.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain www3-vpass.kbqrc.cn has been identified as a credential theft phishing site impersonating the VJAグループ. The domain is currently offline and no longer accessible. This domain was registered through 商中在线科技股份有限公司 and resolves to the IP address 172.67.214.86, which is located in the United States and is part of the AS13335 Cloudflare, Inc. network.
Analysis indicates that the domain was flagged by 18 out of 95 security vendors on VirusTotal, suggesting a significant level of suspicion. The domain was created on May 17, 2025, and has appeared on one security blocklist. The page title found on the domain is 【重要】メンテナンスのお知らせ|VJAグループ Vpass, which translates to 'Important Maintenance Notice | VJA Group Vpass'. The domain does not have an SSL certificate, which is a common indicator of a phishing site. Infrastructure analysis reveals that the domain's IP address is hosted by Cloudflare, a known provider for web services, potentially used to mask the true origin of the threat.
Given the current status of the domain (offline), it is recommended that security teams continue to monitor for any reactivation or similar domains. Additionally, users and employees should be advised to remain vigilant and verify the legitimacy of any communications purportedly from VJAグループ. Security awareness training should emphasize the importance of checking URLs and avoiding entering sensitive information on unsecured sites.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。