franceconcerts[.]fr
“France Concert | Billetterie agrée EU”
franceconcerts.fr — Inhalt nicht verfügbar. Markenidentität: Apple; Betrugstyp: Brand Impersonation. Zusammenfassung der Beweislage: VirusTotal 6/93 (alphaMountain.ai, CRDF, DNS8, Gridinsoft, Seclookup); URLQuery 4 alerts; PhishDestroy score 72/100. Registrar: KEY-SYSTEMS.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
On 24 July 2026, the domain franceconcerts.fr was observed as part of a brand‑impersonation campaign targeting Apple. The site was registered on 21 February 2026 through KEY‑SYSTEMS GmbH and uses GoDaddy’s default nameservers ns81.domaincontrol.com and ns82.domaincontrol.com. DNS resolution points to the IPv4 address 23.227.38.65, which belongs to Cloudflare, Inc. (AS13335) and is geolocated to Canada. No TLS certificate was presented, indicating the site was served over plain HTTP at the time of capture. The page title returned by the HTTP response is “France Concert | Billetterie agrée EU”, which does not reference Apple and suggests the page was repurposed for unrelated content.
The domain appears on a single security blocklist and has been explicitly blocked by the PhishDestroy sink‑hole. In the Open Threat Exchange, the domain is referenced in two separate threat‑intelligence pulses, reinforcing its association with malicious activity. Reputation scoring from Gridinsoft rates the domain at 0 / 100, the lowest possible value. VirusTotal analysis shows six of ninety‑three scanners flagging the domain, confirming that a minority of automated tools recognize it as malicious, while the majority do not yet have a rule for this indicator.
The limited detection footprint, combined with the lack of an SSL certificate and the presence of a generic concert‑ticket page title, suggests the infrastructure was likely a short‑lived drop site used to host a phishing lure for Apple credentials. Because the site is currently offline, live‑traffic observations are unavailable, and the exact payload or credential‑harvesting mechanism cannot be confirmed. Defenders should add 23.227.38.65 and the domain franceconcerts.fr to their deny lists, monitor for future registrations that reuse the same registrar or nameserver configuration, and maintain vigilance for similar brand‑impersonation patterns targeting Apple.
Erkenntnisse zur Netzwerksicherheit
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | franceconcerts.fr/cdn/shopifycloud/importmap-polyfill/es-modules-shim.2.4.0.js |
audit | Hunting_JS_WebAssembly |
| Hagezi Threat Feed | franceconcerts.fr |
malicious | Sinkholed |
| Quad9 DNS | franceconcerts.fr |
malicious | Sinkholed |
| DNS4EU | franceconcerts.fr |
malicious | Sinkholed |
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
VirusTotal-Analyse
Nachweise und externe Berichte
PD-20260203-36CCCF Recipient: abuse@shopify.com Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt