apple896a32f242594befbf0a937ab758af60[.]6eqrvh[.]cn
“8dx4wy.cn | 521: Web server is down”
apple896a32f242594befbf0a937ab758af60.6eqrvh.cn — مغطى بعباءة · يمكن الوصول إليه. انتحال العلامة التجارية: Apple; نوع الاحتيال: Impersonation. ملخص الأدلة: VirusTotal 14/91 (ADMINUSLabs, BitDefender, ESET, Forcepoint ThreatSeeker, Fortinet); Spamhaus DBL_SPAM; cloaking observed; PhishDestroy score 100/100. مسجّل النطاق: 商中在线科技股份有限公司.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
This domain, apple896a32f242594befbf0a937ab758af60.6eqrvh.cn, poses a brand impersonation threat targeting Apple users. The site was designed to mimic legitimate Apple services, likely to harvest credentials, payment details, or distribute malware under the guise of official Apple branding. Such domains often employ convincing visuals and urgent messaging to deceive users into disclosing sensitive information or downloading malicious files. Given the domain's structure and known impersonation tactics, it represents an elevated risk to individuals unfamiliar with phishing indicators. Analysis indicates this domain was created on May 12, 2026, and is registered through 商中在线科技股份有限公司. It is flagged by 22 out of 95 security vendors on VirusTotal, suggesting broad recognition of its malicious intent. The domain resolves to the IP address 188.114.96.3, associated with CloudFlare, Inc., a common hosting provider for both legitimate and malicious sites. The SSL certificate, issued by Google Trust Services, does not validate the site's legitimacy, as certificates can be obtained for any domain. The domain appears on one security blocklist, further confirming its classification as a threat. If you visited apple896a32f242594befbf0a937ab758af60.6eqrvh.cn or interacted with its content, take immediate action to mitigate potential risks. First, disconnect the device from the network to prevent further data transmission. Run a full scan using updated antivirus or anti-malware software to detect and remove any threats. If you entered credentials, change passwords for all accounts accessed from the compromised device, prioritizing financial and email accounts. Enable multi-factor authentication where available. Monitor accounts for unauthorized activity and report any suspicious transactions to the relevant institutions. Consider resetting the device to factory settings if malware is detected or if the device exhibits unusual behavior.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب