secure-app-kaiyun[.]com
“开云体育入口页 - 热门赛事资讯与直播导航 - 即时更新”
Resumen de las pruebas
secure-app-kaiyun.com is an active credential phishing site observed since its registration on May 19, 2026. The page title returned by the server – “开云体育入口页 - 热门赛事资讯与直播导航 - 即时更新” – indicates an attempt to masquerade as a sports portal, likely targeting users of the Kaiyun Sports service. The site responds with HTTP 200, confirming that the front‑end is reachable.
The domain resolves to the IPv4 address 177.210.187.75, which geolocates to Hong Kong. It is hosted behind the nameservers a12.share-dns.com and b12.share-dns.net, both of which are commonly associated with shared DNS services. The TLS certificate is issued by TrustAsia Technologies, Inc. under the LiteSSL RSA CA 2025 hierarchy, providing a valid HTTPS endpoint but offering no indication of legitimate ownership. Registration was performed through Gname.com Pte. Ltd., a registrar known for rapid bulk registrations.
Reputation data shows the domain is listed on three public blocklists and has been flagged by two of ninety‑five VirusTotal scanners, reflecting limited but concrete detection. Gridinsoft assigns a trust score of 0 out of 100, effectively classifying the site as fully untrusted. The URL has been added to block lists maintained by PhishDestroy, MetaMask, and SEAL, and appears in a single AlienVault OTX pulse, reinforcing the consensus that it is used for credential harvesting.
Defenders should immediately block network resolution of secure-app-kaiyun.com and its associated IP address at perimeter firewalls and DNS filtering layers. Continuous monitoring of outbound traffic for authentication attempts to the domain is advised, as the site may be employed to capture user credentials. Given the active SSL certificate, TLS inspection may be required to uncover any hidden data exfiltration. Incident response teams should also correlate any recent login failures or unusual account activity with this domain to identify potentially compromised accounts.
Data Coverage
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 11/08/2026
8 fuentes externas supervisadas Sin coincidencias
Inteligencia de dominios
Detalles técnicosDNS, nombres TLS y marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
Análisis de la configuración del sitio
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.