sap2325b0z[.]cc
“苹果”
sap2325b0z.cc — Belum terverifikasi. Jenis penipuan: Generic Phishing. Ringkasan bukti: VirusTotal 17/91 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao); CF Radar malicious; PhishDestroy score 98/100. Registrar: GoDaddy.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
The domain sap2325b0z.cc was observed serving HTTP content with a 200 response code on July 12, 2026. The site is currently active and is classified as a high‑risk generic phishing operation. Its page title is the Chinese term “苹果,” which directly translates to the Apple brand, indicating a likely attempt to lure users seeking Apple‑related services.
Infrastructure analysis shows the domain resolves to the IPv4 address 38.182.168.147, which is registered to AS40065 (CNSERVERS LLC) in the United States. No TLS certificate is presented, meaning all communications occur over unencrypted HTTP. The domain was registered on July 26, 2025 through GoDaddy.com, LLC and utilizes Cloudflare nameservers (ali.ns.cloudflare.com and piers.ns.cloudflare.com). These details suggest a relatively recent registration coupled with a common hosting provider and a content‑delivery network that can obscure the true origin of the malicious payload.
Threat intelligence sources corroborate the malicious nature of the domain. VirusTotal reports 15 out of 95 security vendors flagging the domain, and it appears on two public blocklists—PhishDestroy and PhishingDB. AlienVault OTX has referenced the domain in fifteen separate threat pulses, and Gridinsoft assigns it a trust score of 0 out of 100, underscoring its low reputation. The combination of a brand‑specific page title, lack of SSL, and multiple independent detections points to a coordinated phishing campaign targeting Apple users.
Defenders should block connections to 38.182.168.147 at the network perimeter and add sap2325b0z.cc to DNS filtering lists. Continuous monitoring of GoDaddy‑registered domains using Cloudflare nameservers for similar patterns is advised. Incident response teams should treat any credentials or session tokens submitted to this domain as compromised and advise affected users to reset passwords and enable multi‑factor authentication where possible.
Intelijen Keamanan Jaringan
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Analisis VirusTotal
Bukti Terarsip
Analisis Konfigurasi Situs
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive