qoq[.]pfz[.]mybluehost[.]me
“iCloud”
qoq.pfz.mybluehost.me — لم يتم التحقق منها. انتحال العلامة التجارية: Apple; نوع الاحتيال: Generic Phishing. ملخص الأدلة: VirusTotal 17/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25); CF Radar malicious; PhishDestroy score 95/100. مسجّل النطاق: Domain.com - Network S….
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
This domain is flagged as an elevated-risk brand impersonation threat targeting Apple iCloud users. Analysis indicates the site was designed to harvest credentials by mimicking the legitimate iCloud login interface, as evidenced by the page title 'iCloud' and confirmed brand impersonation classification. Infrastructure analysis reveals the domain qoq.pfz.mybluehost.me was registered on October 05, 2016, through Domain.com - Network Solutions, LLC. It resolves to the IP address 50.6.34.21, hosted on AS31898 (Oracle Corporation) in Germany. Detection metrics show 18 out of 95 security vendors on VirusTotal flagged the domain as malicious, while it appears on two additional security blocklists. The SSL certificate is issued by Sectigo Limited under the Sectigo Public Server Authentication CA DV R36 chain. The domain has since been taken offline, though it was previously blocked by multiple threat intelligence feeds. Mitigation against this specific threat type involves implementing domain-based email filtering rules to quarantine messages containing references to qoq.pfz.mybluehost.me or its resolved IP. Network administrators should update web proxy and DNS filtering policies to block resolution of the domain and its associated IP. End users should be trained to verify domain authenticity before entering credentials, particularly when prompted by unsolicited login requests. Organizations are advised to monitor for credential reuse attempts, as harvested credentials from this campaign may be leveraged in subsequent account takeover attempts.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب