MALICIOUS — CRITICAL
tap4094y5e[.]cc
17 of 91 security engines flagged the domain; the latest stored check returned HTTP 200.
- VirusTotal
- 17/91
- Blocklists
- No stored match
- التوفر
- مغطى بعباءة · يمكن الوصول إليه · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
tap4094y5e.cc — مغطى بعباءة · يمكن الوصول إليه (HTTP 200). ملخص الأدلة: VirusTotal 17/91 (ADMINUSLabs, Criminal IP, AILabs (MONITORAPP), alphaMountain.ai, BitDefender); cloaking observed; PhishDestroy score 100/100. مسجّل النطاق: GoDaddy.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Digest
tap4094y5e.cc is classified critical with an evidence score of 100/100. 17 of 91 security engines flagged the domain. Registered 30 Jun 2025 via GoDaddy.com, LLC, hosted on 38.182.168.147 (CNSERVERS, US, US). The latest stored check on 9 Aug 2026 returned HTTP 200 and includes a capture.
Stored generated summary (templated)grok · 12/07/2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
Analysis indicates that tap4094y5e.cc was registered on June 30, 2025 through GoDaddy.com, LLC and currently resolves to IP address 38.182.168.147 located in the United States under AS40065. The domain uses nameservers ali.ns.cloudflare.com and piers.ns.cloudflare.com along with an SSL certificate issued by ZeroSSL ECC Domain Secure Site CA. HTTP responses return status 200 and the server advertises HSTS. The page title found is 苹果, directly indicating targeting of Apple. The domain remains active as of the July 12, 2026 report date and is listed on two security blocklists including PhishDestroy and PhishingDB.
VirusTotal reports detections from 17 out of 95 vendors while AlienVault OTX references the domain in 15 threat intelligence pulses. Gridinsoft assigns a trust score of 0 out of 100. These metrics align with the assigned generic_phishing classification and high risk level. Infrastructure details such as the CNSERVERS LLC origin and Cloudflare nameservers are consistent with patterns observed in other flagged domains but do not by themselves confirm malicious intent without additional context.
Exact page content and any login forms or redirection logic have not been retrieved in this assessment, leaving the precise impersonation technique uncertain beyond the recorded page title. Defenders should incorporate the domain and its resolving IP 38.182.168.147 into blocklists and monitoring rules while reviewing logs for connections from internal hosts. Continued observation of the listed nameservers and certificate issuer can support correlation with newly registered domains sharing similar infrastructure. Regular updates from the cited blocklists and OTX pulses provide the most direct means to track persistence or migration of this asset.
نطاق تغطية البيانات12 recorded checks
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 1 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
تحليل VirusTotal
الأدلة المؤرشفة
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of tap4094y5e.cc · checked Mar 1, 2026
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.