22-icloud[.]com
22-icloud.com 피싱 및 보안 점검
“22-icloud.com”
22-icloud.com — 클로킹됨 · 접근 가능 (HTTP 502). 브랜드 사칭: Apple; 사기 유형: Brand Impersonation. 증거 요약: VirusTotal 13/91 (alphaMountain.ai, Emsisoft, Fortinet, G-Data, Gridinsoft); cloaking observed; PhishDestroy score 100/100. 등록기관: Sav.com.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
This domain, 22-icloud.com, is actively impersonating Apple’s iCloud service to deceive users into submitting credentials or personal data. Analysis indicates the site mimics legitimate Apple login pages, likely designed to harvest usernames, passwords, and potentially two-factor authentication codes. The threat extends to possible follow-up attacks, including account takeovers or unauthorized access to linked services such as iTunes, Apple Pay, or iCloud storage. Given the domain’s focus on Apple’s ecosystem, victims may also be targeted for phishing-related financial fraud or identity theft. Infrastructure analysis reveals the domain was registered on June 12, 2026, through Sav.com, LLC, a registrar commonly associated with malicious domains. It resolves to the IP address 207.174.215.249, hosted on AS46606 (Unified Layer), a network frequently observed in phishing campaigns. The domain is flagged by 13 out of 95 security vendors on VirusTotal, and it appears on at least one security blocklist. The SSL certificate, issued by Let’s Encrypt (YR2), provides a false sense of security while failing to validate the site’s legitimacy. Despite its recent creation date, the domain remains active and unmitigated. Users who have visited 22-icloud.com should immediately revoke any entered credentials by changing their Apple ID password and enabling two-factor authentication if not already active. Monitor linked accounts for unauthorized activity, including transactions, device logins, or changes to security settings. If financial data was submitted, contact the relevant institution to report potential fraud. Additionally, scan the device used to access the site for malware, as credential-stealing payloads may have been deployed. Report the domain to security teams or abuse contacts for further investigation and takedown efforts.
위협 대응 Pipeline
공개 차단 목록 상태
저장된 캡처
도메인 인텔리전스
기술적 세부 사항DNS, SSL SAN, 타임스탬프
ICANN OVERSIGHT
인증 및 RAA 상황
인증 및 RAA 상황
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 분석
증거 및 외부 보고서
PD-20260621-A7259C Recipient: abuse@publicdomainregistry.com 이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.