Skip to security report
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 19. Exercise extreme caution — do not enter credentials or personal information.
Domain security and threat intelligence

aisios[.]com[.]cn

Phishing and security check for aisios.com.cn

“爱思助手官网 - 爱思助手官方下载 - 专业苹果iOS刷机验机及设备管理工具”

Threat verdict Critical 100/100 evidence score
Availability Last known active Latest stored reachability observation
Risk signals
VirusTotal detections: 19/91 Spamhaus DBL: DBL_PHISH URLQuery threat systems: 3 alerts Last known active
19/91 VT URLQuery: 3 threat alerts Jun 15, 2026 CDN

Evidence Analysis

Stored analysis · Jul 13, 2026 Ref D0DA9D21

Analysis of the domain aisios.com.cn indicates active impersonation of the legitimate iOS device management tool '爱思助手' (Aisi Assistant). The domain was registered on May 24, 2026, through an undisclosed registrar, with a creation date suggesting recent deployment for malicious purposes. Infrastructure analysis reveals the domain resolves to IP address 188.114.97.3, hosted on Cloudflare infrastructure in Canada, a common tactic to obscure origin and evade takedowns. The site returns an HTTP 200 status, signaling operational availability, and employs a Let's Encrypt SSL certificate (serial number E8), which provides HTTPS encryption but does not validate legitimacy. Detection data from security vendors indicates moderate confidence in malicious classification: 20 of 91 engines flagged the domain on VirusTotal, while PhishDestroy has explicitly blocked it. The domain appears on one additional security blocklist, further corroborating its high-risk status. Gridinsoft assigns a trust score of 0/100, reinforcing the assessment of malicious intent. The page title, '爱思助手官网 - 爱思助手官方下载 - 专业苹果iOS刷机验机及设备管理工具,' explicitly claims affiliation with the legitimate Aisi Assistant brand, suggesting a targeted phishing campaign aimed at Chinese-speaking users seeking iOS device management tools. Technologies detected include Cloudflare and Cloudflare Browser Insights, consistent with modern phishing infrastructure designed to mimic legitimate services while monitoring visitor interactions. The use of HTTP/3 further aligns with current trends in malicious domain deployment. Defenders should prioritize blocking this domain at the DNS and network level, particularly in environments where iOS device management tools are relevant. Further analysis of the site's content and payloads is recommended to determine the exact nature of the phishing mechanism, though no specific payload details are currently available.

VirusTotal
VirusTotal
19 det.
URLQuery
URLQuery
3 threat alerts
CF Radar
Malicious
TLS Certificate
Expired or unverified -10d
Age
3 mo New
Observed status
Last known active 200
PhishDestroy
DestroyList
Listed
Data coverage12 recorded checks
VirusTotal 19 / 91 URLQuery 3 threat-system alerts PhishStats not checked OTX no community references CF Radar provider verdict: malicious URLScan capture not submitted URLScan verdict verdict unavailable DNS blocks not checked TLS Expired or unverified WHOIS 3 mo old Screenshot stored capture Redirect chain not probed
Network Security Intelligence
Threat Detection Systems 3 alerts
Detection System Indicator Verdict Alert
Cloudflare DNS aisios.com.cn malicious Sinkholed
OpenDNS aisios.com.cn phishing Phishing Block
DNS4EU aisios.com.cn malicious Sinkholed
CF Cloudflare Radar Verdict Malicious
Phishing Security Risks Phishing Security threats

Threat Response Pipeline

Discovery
Checks
Reports
Availability
10/12

Public Blocklist Status

Stored Capture

Domain Intelligence

Domain
Server / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden Edge-IP reputation is not attributed to this domain.
IP Address 188.114.97.3 CDN
GeoCA Toronto, CA
NetworkAS13335 · CloudFlare, Inc.
The origin IP is hidden behind a CDN proxy. Reverse-IP results for the edge address contain unrelated tenants; finding the origin requires passive DNS or certificate-transparency data.
RegistrationCreated May 24, 2026 (76d · New)
HTTP Status200
Technical detailsDNS, SSL SANs, timestamps
First DetectedJun 15, 2026
TLS Fingerprint
TLS Observationvalid from May 1, 2026scanned Jun 14, 2026
Favicon Hash
Page Title
爱思助手官网 - 爱思助手官方下载 - 专业苹果iOS刷机验机及设备管理工具
TLS Certificate
Expired or unverified · Issued by Let's Encrypt / E8
Technologies · 3 identified
Cloudflare Browser Insights
Analytics RUM

Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.

www.cloudflare.com 100% confidence
Cloudflare
CDN

Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.

www.cloudflare.com 100% confidence
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org 100% confidence
Detected via Cloudflare Radar · Wappalyzer engine
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

19 / 91 security vendors flagged this domain
View on VT
Last analyzed Previous stored snapshot: 20 detections
ADMINUSLabs
alphaMountain.ai
BitDefender
Chong Lua Dao
Cluster25
CRDF
CyRadar
ESET
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
Kaspersky
Lionic
MalwareURL
SOCRadar
Sophos
VIPRE
Webroot
Site Configuration Analysis
Stored observations are retained with their original collection time.
robots.txt Present · HTTP 200
Valid robots.txt; no Disallow/Allow paths were extracted.
Evidence & External ReportsIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself
Embed This ReportRead-only HTML widget
HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/aisios.com.cn"
  title="PhishDestroy threat report for aisios.com.cn"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>