apple896a32f242594befbf0a937ab758af60[.]6eqrvh[.]cn
“8dx4wy.cn | 521: Web server is down”
apple896a32f242594befbf0a937ab758af60.6eqrvh.cn — Masqué · accessible. Usurpation de l'identité de la marque : Apple; Type d'arnaque : Impersonation. Résumé des preuves: VirusTotal 14/91 (ADMINUSLabs, BitDefender, ESET, Forcepoint ThreatSeeker, Fortinet); Spamhaus DBL_SPAM; cloaking observed; PhishDestroy score 100/100. Bureau d’enregistrement: 商中在线科技股份有限公司.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain, apple896a32f242594befbf0a937ab758af60.6eqrvh.cn, poses a brand impersonation threat targeting Apple users. The site was designed to mimic legitimate Apple services, likely to harvest credentials, payment details, or distribute malware under the guise of official Apple branding. Such domains often employ convincing visuals and urgent messaging to deceive users into disclosing sensitive information or downloading malicious files. Given the domain's structure and known impersonation tactics, it represents an elevated risk to individuals unfamiliar with phishing indicators. Analysis indicates this domain was created on May 12, 2026, and is registered through 商中在线科技股份有限公司. It is flagged by 22 out of 95 security vendors on VirusTotal, suggesting broad recognition of its malicious intent. The domain resolves to the IP address 188.114.96.3, associated with CloudFlare, Inc., a common hosting provider for both legitimate and malicious sites. The SSL certificate, issued by Google Trust Services, does not validate the site's legitimacy, as certificates can be obtained for any domain. The domain appears on one security blocklist, further confirming its classification as a threat. If you visited apple896a32f242594befbf0a937ab758af60.6eqrvh.cn or interacted with its content, take immediate action to mitigate potential risks. First, disconnect the device from the network to prevent further data transmission. Run a full scan using updated antivirus or anti-malware software to detect and remove any threats. If you entered credentials, change passwords for all accounts accessed from the compromised device, prioritizing financial and email accounts. Enable multi-factor authentication where available. Monitor accounts for unauthorized activity and report any suspicious transactions to the relevant institutions. Consider resetting the device to factory settings if malware is detected or if the device exhibits unusual behavior.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif