franceconcerts[.]fr
“France Concert | Billetterie agrée EU”
franceconcerts.fr — Contenido no disponible. Suplantación de marca: Apple; Tipo de estafa: Brand Impersonation. Resumen de las pruebas: VirusTotal 6/93 (alphaMountain.ai, CRDF, DNS8, Gridinsoft, Seclookup); URLQuery 4 alerts; PhishDestroy score 72/100. Registrador: KEY-SYSTEMS.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
On 24 July 2026, the domain franceconcerts.fr was observed as part of a brand‑impersonation campaign targeting Apple. The site was registered on 21 February 2026 through KEY‑SYSTEMS GmbH and uses GoDaddy’s default nameservers ns81.domaincontrol.com and ns82.domaincontrol.com. DNS resolution points to the IPv4 address 23.227.38.65, which belongs to Cloudflare, Inc. (AS13335) and is geolocated to Canada. No TLS certificate was presented, indicating the site was served over plain HTTP at the time of capture. The page title returned by the HTTP response is “France Concert | Billetterie agrée EU”, which does not reference Apple and suggests the page was repurposed for unrelated content.
The domain appears on a single security blocklist and has been explicitly blocked by the PhishDestroy sink‑hole. In the Open Threat Exchange, the domain is referenced in two separate threat‑intelligence pulses, reinforcing its association with malicious activity. Reputation scoring from Gridinsoft rates the domain at 0 / 100, the lowest possible value. VirusTotal analysis shows six of ninety‑three scanners flagging the domain, confirming that a minority of automated tools recognize it as malicious, while the majority do not yet have a rule for this indicator.
The limited detection footprint, combined with the lack of an SSL certificate and the presence of a generic concert‑ticket page title, suggests the infrastructure was likely a short‑lived drop site used to host a phishing lure for Apple credentials. Because the site is currently offline, live‑traffic observations are unavailable, and the exact payload or credential‑harvesting mechanism cannot be confirmed. Defenders should add 23.227.38.65 and the domain franceconcerts.fr to their deny lists, monitor for future registrations that reuse the same registrar or nameserver configuration, and maintain vigilance for similar brand‑impersonation patterns targeting Apple.
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | franceconcerts.fr/cdn/shopifycloud/importmap-polyfill/es-modules-shim.2.4.0.js |
audit | Hunting_JS_WebAssembly |
| Hagezi Threat Feed | franceconcerts.fr |
malicious | Sinkholed |
| Quad9 DNS | franceconcerts.fr |
malicious | Sinkholed |
| DNS4EU | franceconcerts.fr |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
PD-20260203-36CCCF Recipient: abuse@shopify.com ¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.