support-icloudfinds[.]us
“iCloud”
support-icloudfinds.us — Konten tidak tersedia (HTTP 502). Peniruan identitas merek: Apple; Jenis penipuan: Brand Impersonation. Ringkasan bukti: VirusTotal 12/91 (alphaMountain.ai, Fortinet, G-Data, Gridinsoft, SOCRadar); URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 88/100.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
This domain, support-icloudfinds.us, poses a high-risk brand impersonation threat specifically targeting Apple users. The site mimics Apple’s iCloud login portal, designed to harvest credentials, payment details, and personal data from unsuspecting victims. Infrastructure analysis reveals the domain is engineered to exploit trust in Apple’s branding, using deceptive subdomains and visual elements identical to official Apple services. The primary objective is credential theft, which can lead to unauthorized account access, financial fraud, or further exploitation through compromised devices linked to the victim’s Apple ID. Evidence of malicious intent is substantiated by multiple technical indicators. The domain is flagged by 12 out of 95 security vendors on VirusTotal, indicating widespread detection as a phishing resource. It resolves to the IP address 207.174.215.249, hosted under AS46606 (Unified Layer) in the United States, a network frequently associated with fraudulent activities. The domain employs a Let’s Encrypt SSL certificate (YR2), which, while providing encryption, is commonly abused by threat actors to lend a false sense of legitimacy. Additionally, it appears on at least one security blocklist and is actively blocked by enterprise-grade threat intelligence platforms. The domain’s infrastructure and hosting provider further corroborate its classification as a high-risk resource. Users who have visited support-icloudfinds.us or entered credentials on the site should take immediate action to mitigate potential damage. First, revoke access to any sessions or devices linked to the compromised Apple ID via Apple’s official account recovery portal. Enable two-factor authentication (2FA) if not already active, and monitor the account for unauthorized transactions or changes. Reset passwords for any other services where the same credentials may have been reused. If financial information was entered, contact the relevant institution to report potential fraud and request account monitoring. Finally, scan the device used to access the site for malware, as phishing pages may deploy additional payloads or redirect to exploit kits. Users should report the domain to their security team or threat intelligence platforms to aid in broader mitigation efforts.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Analisis VirusTotal
Bukti & Laporan Eksternal
PD-20260621-C25F32 Recipient: abuse@publicdomainregistry.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive