The IP Address(91.204.227.20) has been active since June 23, 2022.
It seems that the domain, or rat ...
show moreThe IP Address(91.204.227.20) has been active since June 23, 2022.
It seems that the domain, or rather, the IP has been abused in setting up phishing sites.
The abused website(s) are looked like still running(active).
You can access the phishing site only from your smartphone (Android OS).
The "japanpost.apk" file for android malware will be downloaded.
Phishing URL:
http://ni.vsbvu.com/sdfgewrwerew/
http://vsbvu.com/sdfgewrwerew/
・Virus Total
https://www.virustotal.com/gui/ip-address/91.204.227.20/relations
・Urlscan
https://urlscan.io/ip/91.204.227.20
https://urlscan.io/result/0c18a7b3-f247-44ba-bbd4-391284af55a0/
https://urlscan.io/result/545e1acf-bfb7-48aa-8a7a-fccfad2331a9/
・Twitter
https://twitter.com/NaomiSuzuki_/status/1545256397717520384
For your information, the fraudulent website appears to be a forgery of this legitimate
website:
https://www.post.japanpost.jp/index.htmlSite owner:
Japan Post Co., Ltd.
show less
The IP Address(192.51.188.108) has been active since June 22, 2022.
It seems that the domain, or ra ...
show moreThe IP Address(192.51.188.108) has been active since June 22, 2022.
It seems that the domain, or rather, the IP has been abused in setting up phishing sites.
The abused website(s) are looked like still running(active).
You can access the phishing site only from your smartphone (Android OS).
When you access the URL, Android malware will be downloaded.
Phishing URL:
http://ljjr.qpaqr.com/fgrrefeedh/
http://qpaqr.com/fgrrefeedh/
・Virus Total
https://www.virustotal.com/gui/ip-address/192.51.188.108/relations
・Urlscan
https://urlscan.io/ip/192.51.188.108
https://urlscan.io/result/5161b8d0-ff0f-4b5d-a517-063bb354074a/
https://urlscan.io/result/e81e00b9-4af9-440c-af6e-1f675d74f565/
For your information, the fraudulent website appears to be a forgery of this legitimate
website:
https://www.post.japanpost.jp/index.htmlSite owner:
Japan Post Co., Ltd.
show less
The IP Address(91.204.227.20) has been active since June 23, 2022.
It seems that the domain, or rat ...
show moreThe IP Address(91.204.227.20) has been active since June 23, 2022.
It seems that the domain, or rather, the IP has been abused in setting up phishing sites.
The abused website(s) are looked like still running(active).
You can access the phishing site only from your smartphone (Android OS).
The "japanpost.apk" file for android malware will be downloaded.
Phishing URL:
http://ni.vsbvu.com/sdfgewrwerew/
http://vsbvu.com/sdfgewrwerew/
・Virus Total
https://www.virustotal.com/gui/ip-address/91.204.227.20/relations
・Urlscan
https://urlscan.io/ip/91.204.227.20
https://urlscan.io/result/78a9e8f7-b233-4c64-8936-aba446f0494c/
https://urlscan.io/result/56ee0bcf-e89c-4cc6-bf58-17df0b738d19/
・Twitter
https://twitter.com/NaomiSuzuki_/status/1545256397717520384
For your information, the fraudulent website appears to be a forgery of this legitimate
website:
https://www.post.japanpost.jp/index.htmlSite owner:
Japan Post Co., Ltd.
show less
The IP Address(91.204.227.20) has been active since June 23, 2022.
It seems that the domain, or rat ...
show moreThe IP Address(91.204.227.20) has been active since June 23, 2022.
It seems that the domain, or rather, the IP has been abused in setting up phishing sites.
The abused website(s) are looked like still running(active).
You can access the phishing site only from your smartphone (Android OS).
The "japanpost.apk" file for android malware will be downloaded.
Phishing URL:
http://ljjr.qpaqr.com/sdfgewrwerew/
http://qpaqr.com/sdfgewrwerew/
・Virus Total
https://www.virustotal.com/gui/ip-address/91.204.227.20/relations
・Urlscan
https://urlscan.io/ip/91.204.227.20
https://urlscan.io/result/1fa95687-8e13-4506-9852-25a7bae0de1a/
https://urlscan.io/result/f67de60a-848b-4ff7-b781-4d4f7d4125b2/
・Twitter
https://twitter.com/goddy222/status/1544939708005826560
For your information, the fraudulent website appears to be a forgery of this legitimate
website:
https://www.post.japanpost.jp/index.htmlSite owner:
Japan Post Co., Ltd.
show less
Since June 23, 2022, the phishing site is currently operating at
IP address: 103.80.134.41
You can ...
show moreSince June 23, 2022, the phishing site is currently operating at
IP address: 103.80.134.41
You can also access the phishing URL only from your smartphone (iOS).
Phishing URL:
http://vvwwlxconn.duckdns.org/ja/main
The following security sites are evidence of phishing sites.
・Virus Total
https://www.virustotal.com/gui/ip-address/103.80.134.41/relations
・Urlscan
https://urlscan.io/ip/103.80.134.41
https://urlscan.io/result/3417f561-adbf-471d-9b52-3250e5100deb/
・Twitter
https://twitter.com/NaomiSuzuki_/status/1544892809433743360
https://twitter.com/NaomiSuzuki_/status/1544867729551020032
https://twitter.com/NaomiSuzuki_/status/1544697123069108224
For your information, the fraudulent website appears to be a forgery of this legitimate
website:
https://appleid.apple.com/ja_JP
Site owner:
Apple inc.
show less
Since June 23, 2022, the phishing site is currently operating at
IP address: 103.80.134.41
You can ...
show moreSince June 23, 2022, the phishing site is currently operating at
IP address: 103.80.134.41
You can also access the phishing URL only from your smartphone (iOS).
Phishing URL:
http://vtpeiradda.duckdns.org/ja/main
http://vkezmfciqy.duckdns.org/ja/main
The following security sites are evidence of phishing sites.
・Virus Total
https://www.virustotal.com/gui/ip-address/103.80.134.41/relations
・Urlscan
https://urlscan.io/ip/103.80.134.41
https://urlscan.io/result/b6688184-00a6-4dcd-aecc-8f156e300b95/
https://urlscan.io/result/74b6a1c0-8998-4a59-b4c6-7d90789fb7c6/
・Twitter
https://twitter.com/NaomiSuzuki_/status/1544892809433743360
https://twitter.com/NaomiSuzuki_/status/1544867729551020032
https://twitter.com/NaomiSuzuki_/status/1544697123069108224
For your information, the fraudulent website appears to be a forgery of this legitimate
website:
https://appleid.apple.com/ja_JP
Site owner:
Apple inc.
show less
From around July 7, 2022, a phishing email ([email protected]) attempting to steal credit card inf ...
show moreFrom around July 7, 2022, a phishing email ([email protected]) attempting to steal credit card information was detected by deceiving Japan Post.
The IP addresses of the phishing URLs are 172.67.181.98 and 104.21.67.215.
Phishing URL:
https://pricesprivacymarketplace.top/index.php
↓
https://pricesprivacymarketplace.top/yz.php
↓
https://pricesprivacymarketplace.top/TokenYz.php
↓
https://pricesprivacymarketplace.top/Information.php
↓
https://pricesprivacymarketplace.top/postUserinfo.php
<Evidence>
・Twitter in Japanese
情弱返上?悪玉ちゃん!@cX8oKyVKoqucXfR
https://twitter.com/cX8oKyVKoqucXfR/status/1544902261620367361
・Urlscan.io
https://urlscan.io/result/3ea59834-f003-454e-a0a1-f69cadc7b681/
https://urlscan.io/result/f48e6496-25a6-4270-8439-ac2183b906e5/
・Virus Total
https://www.virustotal.com/gui/domain/pricesprivacymarketplace.top/relations
https://www.virustotal.com/gui/ip-address/172.67.181.98/relations
https://www.virustotal.com/gui/ip-address/104.21.67.215/relations
show less
From around July 7, 2022, a phishing email ([email protected]) attempting to steal credit card inf ...
show moreFrom around July 7, 2022, a phishing email ([email protected]) attempting to steal credit card information was detected by deceiving Japan Post.
The IP addresses of the phishing URLs are 172.67.181.98 and 104.21.67.215.
Phishing URL:
https://pricesprivacymarketplace.top/index.php
↓
https://pricesprivacymarketplace.top/yz.php
↓
https://pricesprivacymarketplace.top/TokenYz.php
↓
https://pricesprivacymarketplace.top/Information.php
↓
https://pricesprivacymarketplace.top/postUserinfo.php
<Evidence>
・Twitter in Japanese
情弱返上?悪玉ちゃん!@cX8oKyVKoqucXfR
https://twitter.com/cX8oKyVKoqucXfR/status/1544902261620367361
・Urlscan.io
https://urlscan.io/result/3ea59834-f003-454e-a0a1-f69cadc7b681/
https://urlscan.io/result/f48e6496-25a6-4270-8439-ac2183b906e5/
・Virus Total
https://www.virustotal.com/gui/domain/pricesprivacymarketplace.top/relations
https://www.virustotal.com/gui/ip-address/172.67.181.98/relations
https://www.virustotal.com/gui/ip-address/104.21.67.215/relations
show less
Since June 23, 2022, the phishing site is currently operating at
IP address: 103.80.134.41
You can ...
show moreSince June 23, 2022, the phishing site is currently operating at
IP address: 103.80.134.41
You can also access the phishing URL only from your smartphone (iOS).
Phishing URL:
http://vdkwriggtj.duckdns.org/ja/main
The following security sites are evidence of phishing sites.
・Virus Total
https://www.virustotal.com/gui/ip-address/103.80.134.41/relations
・Urlscan
https://urlscan.io/ip/103.80.134.41
https://urlscan.io/result/22dc6b47-8a31-4fbd-803c-f31445a0933b/
・Twitter
https://twitter.com/NaomiSuzuki_/status/1544892809433743360
https://twitter.com/NaomiSuzuki_/status/1544867729551020032
https://twitter.com/NaomiSuzuki_/status/1544697123069108224
For your information, the fraudulent website appears to be a forgery of this legitimate
website:
https://appleid.apple.com/ja_JP
Site owner:
Apple inc.
show less
The IP Address(91.204.227.20) has been active since June 23, 2022.
It seems that the domain, or rat ...
show moreThe IP Address(91.204.227.20) has been active since June 23, 2022.
It seems that the domain, or rather, the IP has been abused in setting up phishing sites.
The abused website(s) are looked like still running(active).
You can access the phishing site only from your smartphone (Android OS).
The "japanpost.apk" file for android malware will be downloaded.
Phishing URL:
http://yql.bznrm.com/sdfgewrwerew/
http://l.yxmnu.com/sdfgewrwerew/
・Virus Total
https://www.virustotal.com/gui/ip-address/91.204.227.20/relations
・Urlscan
https://urlscan.io/ip/91.204.227.20
https://urlscan.io/result/93db156a-4d2e-4e2f-b613-e0979b6d4c3b/
https://urlscan.io/result/ed5fa258-2d4a-4eb2-97e2-450987e5f5b3/
・Twitter
https://twitter.com/NaomiSuzuki_/status/1544524414720815104
For your information, the fraudulent website appears to be a forgery of this legitimate
website:
https://www.post.japanpost.jp/index.htmlSite owner:
Japan Post Co., Ltd.
show less
The IP Address(192.51.188.108) has been active since June 22, 2022.
It seems that the domain, or ra ...
show moreThe IP Address(192.51.188.108) has been active since June 22, 2022.
It seems that the domain, or rather, the IP has been abused in setting up phishing sites.
The abused website(s) are looked like still running(active).
You can access the phishing site only from your smartphone (Android OS).
When you access the URL, Android malware will be downloaded.
Phishing URL:
http://uw9j.rdybz.com/fgrrefeedh/
http://pn.uzshq.com/fgrrefeedh/
・Virus Total
https://www.virustotal.com/gui/ip-address/192.51.188.108/relations
・Urlscan
https://urlscan.io/ip/192.51.188.108
https://urlscan.io/result/31ed5ae2-b210-4063-975d-ca265de7de65/
https://urlscan.io/result/7c89be63-66d5-4746-bd28-2080d783a43f/
For your information, the fraudulent website appears to be a forgery of this legitimate
website:
https://www.post.japanpost.jp/index.htmlSite owner:
Japan Post Co., Ltd.
show less
Since June 23, 2022, the phishing site is currently operating at
IP address: 103.80.134.41
You can ...
show moreSince June 23, 2022, the phishing site is currently operating at
IP address: 103.80.134.41
You can also access the phishing URL only from your smartphone (iOS).
Phishing URL:
http://treeerdbab.duckdns.org/ja/main
The following security sites are evidence of phishing sites.
・Virus Total
https://www.virustotal.com/gui/ip-address/103.80.134.41/relations
・Urlscan
https://urlscan.io/ip/103.80.134.41
https://urlscan.io/result/40ec13ac-7866-495d-8294-ef80ce13042a/
・Twitter
https://twitter.com/NaomiSuzuki_/status/1544505476603609089
https://twitter.com/NaomiSuzuki_/status/1544325778053414912
https://twitter.com/NaomiSuzuki_/status/1544524414720815104
For your information, the fraudulent website appears to be a forgery of this legitimate
website:
https://appleid.apple.com/ja_JP
Site owner:
Apple inc.
show less
From around July 4, 2022, a phishing email ([email protected]) attempting to steal credit card ...
show moreFrom around July 4, 2022, a phishing email ([email protected]) attempting to steal credit card information was detected by deceiving Japan Post.
The IP addresses of the phishing URLs are 104.21.76.105 and 172.67.193.15.
<Phishing URL>
https://websitelppostsecure.top/index.php
↓
https://websitelppostsecure.top/yz.php
↓
https://websitelppostsecure.top/TokenYz.php
↓
https://websitelppostsecure.top/Information.php
↓
https://websitelppostsecure.top/postUserinfo.php
<Evidence>
・Twitter in Japanese
https://twitter.com/JJTake/status/1544510882709110784
・ Virus Total
https://www.virustotal.com/gui/domain/websitelppostsecure.top/relations
https://www.virustotal.com/gui/ip-address/104.21.76.105/relations
https://www.virustotal.com/gui/ip-address/172.67.193.15/relations
・Urlscan
https://urlscan.io/result/51acdb0e-9e0a-4b6f-b3d0-02e86343b2bd/
https://urlscan.io/result/3bf8c189-ba23-438a-bbf9-61e08013b177/
show less
From around July 4, 2022, a phishing email ([email protected]) attempting to steal credit card ...
show moreFrom around July 4, 2022, a phishing email ([email protected]) attempting to steal credit card information was detected by deceiving Japan Post.
The IP addresses of the phishing URLs are 104.21.76.105 and 172.67.193.15.
<Phishing URL>
https://websitelppostsecure.top/index.php
↓
https://websitelppostsecure.top/yz.php
↓
https://websitelppostsecure.top/TokenYz.php
↓
https://websitelppostsecure.top/Information.php
↓
https://websitelppostsecure.top/postUserinfo.php
<Evidence>
・Twitter in Japanese
https://twitter.com/JJTake/status/1544510882709110784
・ Virus Total
https://www.virustotal.com/gui/domain/websitelppostsecure.top/relations
https://www.virustotal.com/gui/ip-address/104.21.76.105/relations
https://www.virustotal.com/gui/ip-address/172.67.193.15/relations
・Urlscan
https://urlscan.io/result/51acdb0e-9e0a-4b6f-b3d0-02e86343b2bd/
https://urlscan.io/result/3bf8c189-ba23-438a-bbf9-61e08013b177/
show less
The IP Address(91.204.227.20) has been active since June 23, 2022.
It seems that the domain, or rat ...
show moreThe IP Address(91.204.227.20) has been active since June 23, 2022.
It seems that the domain, or rather, the IP has been abused in setting up phishing sites.
The abused website(s) are looked like still running(active).
You can access the phishing site only from your smartphone (Android OS).
The "japanpost.apk" file for android malware will be downloaded.
Phishing URL:
http://wuvqq.com/sdfgewrwerew/
http://yermu.com/sdfgewrwerew/
・Virus Total
https://www.virustotal.com/gui/ip-address/91.204.227.20/relations
・Urlscan
https://urlscan.io/ip/91.204.227.20
https://urlscan.io/result/9ab80203-3520-4bc5-9809-3eaad5ceecf9/
https://urlscan.io/result/cc29b498-173e-4bdc-bbdf-ba77bf3e9346/
・Twitter
https://twitter.com/NaomiSuzuki_/status/1544171287337381888
https://twitter.com/NaomiSuzuki_/status/1544179252270362625
For your information, the fraudulent website appears to be a forgery of this legitimate
website:
https://www.post.japanpost.jp/index.htmlSite owner:
Japan Post Co., Ltd.
show less
The IP Address(192.51.188.108) has been active since June 22, 2022.
It seems that the domain, or ra ...
show moreThe IP Address(192.51.188.108) has been active since June 22, 2022.
It seems that the domain, or rather, the IP has been abused in setting up phishing sites.
The abused website(s) are looked like still running(active).
You can access the phishing site only from your smartphone (Android OS).
When you access the URL, Android malware will be downloaded.
Phishing URL:
http://o.mzsac.com/fgrrefeedh/
http://b.hyeyu.com/fgrrefeedh/
・Virus Total
https://www.virustotal.com/gui/ip-address/192.51.188.108/relations
・Urlscan
https://urlscan.io/ip/192.51.188.108
https://urlscan.io/result/e7a399cd-d5f6-4784-b586-bf4110ceaab8/
https://urlscan.io/result/fe0f311d-ac8d-438c-b571-b6735b9a2314/
For your information, the fraudulent website appears to be a forgery of this legitimate
website:
https://www.post.japanpost.jp/index.htmlSite owner:
Japan Post Co., Ltd.
show less
The IP Address(91.204.227.20) has been active since June 23, 2022.
It seems that the domain, or rat ...
show moreThe IP Address(91.204.227.20) has been active since June 23, 2022.
It seems that the domain, or rather, the IP has been abused in setting up phishing sites.
The abused website(s) are looked like still running(active).
You can access the phishing site only from your smartphone (Android OS).
The "japanpost.apk" file for android malware will be downloaded.
Phishing URL:
http://j.uzshq.com/sdfgewrwerew/
・Virus Total
https://www.virustotal.com/gui/ip-address/91.204.227.20/relations
・Urlscan
https://urlscan.io/ip/91.204.227.20
https://urlscan.io/result/e26f4a90-10d5-4ea8-8e0a-a2f001ce2cf7/
https://urlscan.io/result/16d903d5-039b-4d4c-8908-1b2b5b9016d6/
・Twitter
https://twitter.com/NaomiSuzuki_/status/1544160030504910848
For your information, the fraudulent website appears to be a forgery of this legitimate
website:
https://www.post.japanpost.jp/index.htmlSite owner:
Japan Post Co., Ltd.
show less
Since June 23, 2022, the phishing site is currently operating at
IP address: 103.80.134.41
You can ...
show moreSince June 23, 2022, the phishing site is currently operating at
IP address: 103.80.134.41
You can also access the phishing URL only from your smartphone (iOS).
Phishing URL:
http://skbxahkjgz.duckdns.org/ja/main
The following security sites are evidence of phishing sites.
・Virus Total
https://www.virustotal.com/gui/ip-address/103.80.134.41/relations
・Urlscan
https://urlscan.io/ip/103.80.134.41
https://urlscan.io/result/a50df64f-a7f2-42db-a211-9a66d46e7da2/
・Twitter
https://twitter.com/NaomiSuzuki_/status/1544160030504910848
https://twitter.com/NaomiSuzuki_/status/1544140894278131712
https://twitter.com/NaomiSuzuki_/status/1543970492667039744
For your information, the fraudulent website appears to be a forgery of this legitimate
website:
https://appleid.apple.com/ja_JP
Site owner:
Apple inc.
show less
From around July 4, 2022, a phishing email ([email protected]) attempting to steal credit card ...
show moreFrom around July 4, 2022, a phishing email ([email protected]) attempting to steal credit card information was detected by deceiving Japan Post.
The IP addresses of the phishing URLs are 104.21.76.105 and 172.67.193.15.
<Phishing URL>
https://websitelppostsecure.top/index.php
↓
https://websitelppostsecure.top/yz.php
↓
https://websitelppostsecure.top/TokenYz.php
↓
https://websitelppostsecure.top/Information.php
↓
https://websitelppostsecure.top/postUserinfo.php
<Evidence>
・Twitter in Japanese
https://twitter.com/catnap707/status/1543878651489333248
https://twitter.com/KesaGataMe0/status/1543862251152867328
・ Virus Total
https://www.virustotal.com/gui/domain/websitelppostsecure.top/relations
https://www.virustotal.com/gui/ip-address/104.21.76.105/relations
https://www.virustotal.com/gui/ip-address/172.67.193.15/relations
・Urlscan
https://urlscan.io/result/42984bf7-30fd-45bd-a98c-81cb7ab3714e/
https://urlscan.io/result/12e329cb-d6e3-4cde-b008-20ac0e654c2a/
show less
From around July 4, 2022, a phishing email ([email protected]) attempting to steal credit card ...
show moreFrom around July 4, 2022, a phishing email ([email protected]) attempting to steal credit card information was detected by deceiving Japan Post.
The IP addresses of the phishing URLs are 104.21.76.105 and 172.67.193.15.
<Phishing URL>
https://websitelppostsecure.top/index.php
↓
https://websitelppostsecure.top/yz.php
↓
https://websitelppostsecure.top/TokenYz.php
↓
https://websitelppostsecure.top/Information.php
↓
https://websitelppostsecure.top/postUserinfo.php
<Evidence>
・Twitter in Japanese
https://twitter.com/catnap707/status/1543878651489333248
https://twitter.com/KesaGataMe0/status/1543862251152867328
・ Virus Total
https://www.virustotal.com/gui/domain/websitelppostsecure.top/relations
https://www.virustotal.com/gui/ip-address/104.21.76.105/relations
https://www.virustotal.com/gui/ip-address/172.67.193.15/relations
・Urlscan
https://urlscan.io/result/42984bf7-30fd-45bd-a98c-81cb7ab3714e/
https://urlscan.io/result/12e329cb-d6e3-4cde-b008-20ac0e654c2a/
show less
Since June 23, 2022, the phishing site is currently operating at
IP address: 103.80.134.41
You can ...
show moreSince June 23, 2022, the phishing site is currently operating at
IP address: 103.80.134.41
You can also access the phishing URL only from your smartphone (iOS).
Phishing URL:
http://qwfhjigjsy.duckdns.org/ja/main
http://qrsxxlyyym.duckdns.org/ja/main
The following security sites are evidence of phishing sites.
・Virus Total
https://www.virustotal.com/gui/ip-address/103.80.134.41/relations
・Urlscan
https://urlscan.io/ip/103.80.134.41
https://urlscan.io/result/15e01e19-5b10-4c74-9fe6-487e40412a04/
https://urlscan.io/result/4c0bcf23-a11e-4299-861c-65dc582310e8/
・Twitter
https://twitter.com/NaomiSuzuki_/status/1543782602364141569
https://twitter.com/NaomiSuzuki_/status/1543596676291899395
For your information, the fraudulent website appears to be a forgery of this legitimate
website:
https://appleid.apple.com/ja_JP
Site owner:
Apple inc.
show less
The IP Address(91.204.227.20) has been active since June 23, 2022.
It seems that the domain, or rat ...
show moreThe IP Address(91.204.227.20) has been active since June 23, 2022.
It seems that the domain, or rather, the IP has been abused in setting up phishing sites.
The abused website(s) are looked like still running(active).
You can access the phishing site only from your smartphone (Android OS).
The "japanpost.apk" file for android malware will be downloaded.
Phishing URL:
http://f.ubzuu.com/sdfgewrwerew/
http://2o.ubzuu.com/sdfgewrwerew/
・Virus Total
https://www.virustotal.com/gui/ip-address/91.204.227.20/relations
・Urlscan
https://urlscan.io/ip/91.204.227.20
https://urlscan.io/result/fad77e65-eaab-440d-bbf1-3c6469596732/
https://urlscan.io/result/1fc2fe93-d670-400c-98f6-9f4e6d047526/
・Twitter
https://twitter.com/NaomiSuzuki_/status/1543821535966035969
https://twitter.com/NaomiSuzuki_/status/1543833702891147265
For your information, the fraudulent website appears to be a forgery of this legitimate
website:
https://www.post.japanpost.jp/index.htmlSite owner:
Japan Post Co., Ltd.
show less
The IP Address(192.51.188.108) has been active since June 22, 2022.
It seems that the domain, or ra ...
show moreThe IP Address(192.51.188.108) has been active since June 22, 2022.
It seems that the domain, or rather, the IP has been abused in setting up phishing sites.
The abused website(s) are looked like still running(active).
You can access the phishing site only from your smartphone (Android OS).
When you access the URL, Android malware will be downloaded.
Phishing URL:
http://hyeyu.com/fgrrefeedh/
http://3.zyhvu.com/fgrrefeedh/
・Virus Total
https://www.virustotal.com/gui/ip-address/192.51.188.108/relations
・Urlscan
https://urlscan.io/ip/192.51.188.108
https://urlscan.io/result/9e5eaee7-11d2-44e2-bf59-cb1a14d055b5/
https://urlscan.io/result/975daf4c-1fdc-486f-b138-70817d48bf3e/
For your information, the fraudulent website appears to be a forgery of this legitimate
website:
https://www.post.japanpost.jp/index.htmlSite owner:
Japan Post Co., Ltd.
show less
Since June 23, 2022, the phishing site is currently operating at
IP address: 103.80.134.41
You can ...
show moreSince June 23, 2022, the phishing site is currently operating at
IP address: 103.80.134.41
You can also access the phishing URL only from your smartphone (iOS).
Phishing URL:
http://qpcpbonzyx.duckdns.org/ja/main
http://qhhkkwxwhj.duckdns.org/ja/main
http://qcccdiivhh.duckdns.org/ja/main
The following security sites are evidence of phishing sites.
・Virus Total
https://www.virustotal.com/gui/ip-address/103.80.134.41/relations
・Urlscan
https://urlscan.io/ip/103.80.134.41
https://urlscan.io/result/fd481b40-69dd-4a38-99b9-ea84d786bbe1/
https://urlscan.io/result/83ce9a17-77d6-4f8f-adee-1857de3cc6bd/
https://urlscan.io/result/08fe10f8-f5d7-477a-ba0d-038157e7df10/
・Twitter
https://twitter.com/NaomiSuzuki_/status/1543782602364141569
https://twitter.com/NaomiSuzuki_/status/1543596676291899395
For your information, the fraudulent website appears to be a forgery of this legitimate
website:
https://appleid.apple.com/ja_JP
Site owner:
Apple inc.
show less
The IP Address(91.204.227.20) has been active since June 23, 2022.
It seems that the domain, or rat ...
show moreThe IP Address(91.204.227.20) has been active since June 23, 2022.
It seems that the domain, or rather, the IP has been abused in setting up phishing sites.
The abused website(s) are looked like still running(active).
You can access the phishing site only from your smartphone (Android OS).
The "japanpost.apk" file for android malware will be downloaded.
Phishing URL:
http://rdybz.com/sdfgewrwerew/
http://hs1n.rdybz.com/sdfgewrwerew/
・Virus Total
https://www.virustotal.com/gui/ip-address/91.204.227.20/relations
・Urlscan
https://urlscan.io/ip/91.204.227.20
https://urlscan.io/result/4a2162b0-b1cd-4e10-acab-c60366cb88ce/
https://urlscan.io/result/9f8aa986-08a8-45b8-8e4f-c30044f6c6da/
・Twitter
https://twitter.com/NaomiSuzuki_/status/1543821535966035969
https://twitter.com/NaomiSuzuki_/status/1543833702891147265
For your information, the fraudulent website appears to be a forgery of this legitimate
website:
https://www.post.japanpost.jp/index.htmlSite owner:
Japan Post Co., Ltd.
show less
PhishingEmail SpamExploited Host
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.