maps-icloudmy1[.]us
“iCloud”
maps-icloudmy1.us — مغطى بعباءة · يمكن الوصول إليه. انتحال العلامة التجارية: Apple; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 10/91 (alphaMountain.ai, Cluster25, CRDF, G-Data, Google Safebrowsing); URLScan malicious verdict; Google Safe Browsing flagged; cloaking observed; PhishDestroy score 100/100.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain maps-icloudmy1.us was flagged as a high‑risk brand‑impersonation operation targeting Apple. Infrastructure analysis shows the domain resolves to IP 207.174.215.249, which belongs to the Unified Layer network (AS46606) in the United States. The site was served over a Let’s Encrypt certificate, indicating TLS support but offering no validation of legitimacy. Nameserver records point to ns1.md-35.webhostbox.net and ns2.md-35.webhostbox.net, typical of transient hosting services used by malicious actors.
Reputation services have taken consistent action: PhishDestroy lists the domain as blocked, Google Safe Browsing classifies it under social‑engineering, and a single public blocklist also contains the entry. VirusTotal reports that ten of ninety‑one scanners flag the domain, confirming detectable malicious components. The Gridinsoft trust score of 0 out of 100 further underscores the lack of confidence in the host.
The domain’s current status is offline, suggesting the hosting provider or takedown efforts have removed active content, but the historical footprint remains relevant for threat‑intel correlation. Defenders should continue to monitor the associated IP range and hosting provider for related activity, update web‑filtering and email‑gateway rules to block the domain and its IP, and ensure endpoint detections include the ten VirusTotal‑identified signatures. Because the site’s exact page content and any credential‑capture mechanisms have not been publicly disclosed, further analysis of archived snapshots, if available, would be advisable to confirm the phishing vector employed.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة والتقارير الخارجية
PD-20260621-5D27C6 Recipient: abuse@publicdomainregistry.com هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب