apple[.]cert-sha256[.]co[.]uk
apple.cert-sha256.co.uk — Belum terverifikasi. Peniruan identitas merek: Apple; Jenis penipuan: Generic Phishing. Ringkasan bukti: VirusTotal 2/94 (Criminal IP, alphaMountain.ai, CRDF, CyRadar); PhishDestroy score 71/100. Registrar: Gandi.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
This domain is flagged as an elevated-risk credential harvesting site targeting Apple users. Analysis indicates the infrastructure was specifically designed to mimic Apple’s authentication portals, likely to capture Apple ID credentials, payment details, or two-factor authentication codes. The threat type falls under brand impersonation with a focus on credential theft, a common precursor to account takeover and financial fraud. Infrastructure analysis reveals the domain apple.cert-sha256.co.uk was registered on March 27, 2026, through Gandi, a registrar frequently exploited for phishing operations. The site was hosted with an Amazon-issued SSL certificate, a tactic used to lend false legitimacy to fraudulent pages. At the time of assessment, the domain was taken offline but had been blocked by PhishDestroy and appeared on one security blocklist. VirusTotal detection rates showed 4 out of 95 security vendors flagged the domain as malicious. Technologies detected include Bootstrap, a framework often used to rapidly deploy convincing phishing templates, and HSTS, which may have been spoofed to bypass browser security warnings. Mitigation steps for this threat type include immediate blacklisting of the domain across all security gateways and endpoint protection systems. Network administrators should ensure DNS resolvers block resolution of apple.cert-sha256.co.uk and monitor for residual connections from compromised devices. Organizations should also implement DMARC, DKIM, and SPF policies to prevent similar brand impersonation attempts via email. End users who may have interacted with the domain should be instructed to reset their Apple ID credentials from a verified Apple portal and enable multi-factor authentication. Security teams should review logs for any successful connections to the domain and conduct a forensic analysis of potentially affected systems.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Teknologi · 2 identified
Bootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
getbootstrap.com Keyakinan 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Keyakinan 100%Analisis VirusTotal
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of apple.cert-sha256.co.uk · checked Jun 26, 2026
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive