MALICIOUS — CRITICAL
aptmdao[.]io
As of July 22, 2026, the domain aptmdao.io is flagged as a credential phishing site with a high risk level.
- VirusTotal
- 16/91
- Blocklists
- No stored match
- التوفر
- آخر نشاط معروف · HTTP 308
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
aptmdao.io — آخر نشاط معروف (HTTP 308). نوع الاحتيال: Credential Phishing. ملخص الأدلة: VirusTotal 16/91 (alphaMountain.ai, Bfore.Ai PreCrime, BitDefender, Chong Lua Dao, CRDF); PhishDestroy score 100/100. مسجّل النطاق: Namecheap.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
As of July 22, 2026, the domain aptmdao.io is flagged as a credential phishing site with a high risk level. The domain was created on June 09, 2026, and is currently active, indicating a recent and ongoing threat. Analysis reveals that the domain is registered through NAMECHEAP INC and uses Cloudflare for DNS and hosting services, with nameservers ophelia.ns.cloudflare.com and rene.ns.cloudflare.com. The domain resolves to the IP address 104.21.96.12, which is located in California, USA, and is associated with Cloudflare, Inc. The MX record points to smtp.google.com, suggesting the use of Google's SMTP servers for email handling.
The SSL certificate is issued by Google Trust Services / WE1, which might lend a false sense of security to users. The page title 'Login - Apertum DAO' implies that the domain is attempting to mimic a legitimate login page, likely for a decentralized autonomous organization (DAO) named Apertum. However, the exact content and design of the page are not yet analyzed, and users should not assume the site's legitimacy based on the page title alone. The domain is detected and blocked by several security vendors, including PhishDestroy, MetaMask, and SEAL, and appears on three security blocklists.
The HTTP status code 308 suggests a permanent redirect, which could be used to mask the actual destination of the page. Given the high risk level and the presence on multiple blocklists, defenders should consider blocking access to this domain and educating users about the risks of credential phishing. Users should verify the authenticity of any login pages they encounter and avoid entering sensitive information on untrusted sites.
نطاق تغطية البيانات13 recorded checks
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
المراجع المتقاطعة لاستخبارات التهديدات · source references
التقنيات · 7 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org ثقة 100٪React is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org ثقة 100٪Next.js is a React framework for developing single page Javascript applications.
nextjs.org ثقة 100٪Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com ثقة 100٪Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
الأدلة المؤرشفة
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of aptmdao.io · checked Jul 19, 2026
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.