www3-vpass[.]xidkz[.]cn
“【重要】メンテナンスのお知らせ|VJAグループ Vpass”
www3-vpass.xidkz.cn — 内容不可用. 证据摘要: VirusTotal 18/95 (ADMINUSLabs, Criminal IP, BitDefender, Chong Lua Dao, CyRadar); CF Radar malicious; PhishDestroy score 95/100. 注册商: 商中在线科技股份有限公司.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, www3-vpass.xidkz.cn, presents itself as a maintenance notice page for the VJA Group Vpass service, based on its page title. The threat it poses is that of a phishing or credential harvesting site, specifically impersonating the legitimate Vpass cardmember portal to trick users into entering sensitive login information under the guise of a system update.
Technical evidence shows the site was flagged by 18 out of 95 VirusTotal vendors, including ADMINUSLabs, Criminal IP, BitDefender, Chong Lua Dao, and CyRadar, and appears on 2 blocklists. It is hosted on IP address 172.67.128.191, located in the United States, and registered to Cloudflare, Inc. (AS13335). The domain was created on 2025-05-17 via registrar 商中在线科技股份有限公司, using nameservers bethany.ns.cloudflare.com and moura.ns.cloudflare.com, with an SSL certificate from Let's Encrypt (R12).
The site is currently offline or unreachable. The risk level is high due to the recent creation date, high detection rate, and impersonation of a known financial brand. Users who may have interacted with this site are advised to change their Vpass credentials immediately.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。