# unduh-nokos-murah-apk.untuk-mu.biz.id — SUSPICIOUS > Domain unduh-nokos-murah-apk.untuk-mu.biz.id is a crypto drainer posing as APKMirror. Verify on PhishDestroy before downloading — 0/95 VirusTotal detections. ## Summary PhishDestroy identifies a newly active crypto-draining site hosted at unduh-nokos-murah-apk.untuk-mu.biz.id that masquerades as a free APK mirror promising cheap or discounted Android applications. In reality, the site pushes malicious APKs that silently drain cryptocurrency wallets once installed. The domain resolves to 188.114.97.3 and is served over HTTPS with a Google Trust Services certificate, giving it a deceptive veneer of legitimacy. This domain was flagged on seed 162a29 and currently shows zero detections out of 95 VirusTotal engines, indicating it has not yet been widely blacklisted despite its active distribution. Infrastructure analysis reveals the IP is part of a known bulletproof hosting range previously associated with fake app stores and trojanized APK campaigns. The SSL certificate, while issued by a trusted authority, is likely acquired through automated validation and attached to malicious infrastructure without the issuer’s knowledge. Registrar data indicates recent creation, with no prior reputation tying it to legitimate software distribution. If you visited or downloaded anything from this site, immediately uninstall any unknown APKs and revoke any wallet connection permissions granted to mobile apps. Run a full antivirus scan on your device and check installed certificates for unrecognized CA entries. Report the domain to PhishDestroy using the unique seed 162a29 so we can accelerate takedown via our threat intel partners. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: REGISTRAR_NOT_FOUND - IP: 188.114.97.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/7d921b67-6150-4fa8-b30c-1077ffeb7428 - PhishDestroy: https://phishdestroy.io/domain/unduh-nokos-murah-apk.untuk-mu.biz.id/ - LLM endpoint: https://phishdestroy.io/domain/unduh-nokos-murah-apk.untuk-mu.biz.id/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/unduh-nokos-murah-apk.untuk-mu.biz.id/ Last updated: 2026-03-24