Japanese live-operator phishing panel (SMBC Vpass / docomo / Eki-net) — known hosts (2 of 2)
Phishing sites aimed at people in Japan that imitate the SMBC Card member service 'Vpass', NTT docomo's 'd account' login and JR East's 'Eki-net', all built from one kit with numbered brand templates. The fake login page sends every keystroke of the ID and password to a live operator over a WebSocket connection and holds each submission until the operator moves the visitor on: card number, expiry date and security code, a one-time-code page styled for Visa, Mastercard, JCB or American Express, the card PIN, and phone or app verification. The sites answer only on the long, unique link sent to the victim (for example /login/smbc-CARD/lndex.html/entathl/jsp or /member/account/security/verification/account-information/details); the bare domain and every other path redirect to the real brand's website, so visiting the domain alone shows the genuine page. Hosts are short-lived: pinyin-style .com names registered many months before use and random .top names (e.g. teruid[.]com, rslny[.]com, szcxmd[.]com, zhongxiaokeji[.]com, xwqymywqsnswqhhq[.]top) on cloud servers in Singapore, and their DNS is often removed within hours. Seen since at least early July 2026. SMBC Card, docomo and JR East do not ask for a card PIN or one-time codes through a link in a text message or e-mail.
Anchors
domain:spbkxizjanfz.top OR domain:sukljbcatzainmhm.top OR domain:szcxmd.com OR domain:taoanji.com OR domain:teruid.com OR domain:tmallgraceful.com OR domain:tmalllyrical.com OR domain:tmallpoetic.com OR domain:tuopuzhaofeng.com OR domain:wakdwfelxdhzjvr.top OR domain:xiangjixuan.com OR domain:xianqoo.com OR domain:xwqymywqsnswqhhq.top OR domain:yuanjicehua.com OR domain:zhongxiaokeji.com OR domain:zigonghongshun.comProvenance
Sightings (1)
| Host | Scan | Script | Match | When |
|---|---|---|---|---|
| szcxmd.com | 913eda92… | — | query | 2026-10-02 10:02 |