capcuteapk[.]com
“CapCut Apk Download 15.10.13 Latest Version Full Unlocked Without Watermark 2025”
Resumo das evidências
On July 22, 2026 the domain capcuteapk.com was observed as an active threat vector targeting the Instagram brand. The site was registered through Dynadot LLC on February 14, 2025 and is hosted on Cloudflare infrastructure (AS13335) with the IP address 188.114.97.3 located in the United States. DNS resolution uses the Cloudflare nameservers hugh.ns.cloudflare.com and iris.ns.cloudflare.com. No HTTPS certificate was presented, indicating the site served content over plain HTTP only. The page title retrieved from the live host read "CapCut Apk Download 15.10.13 Latest Version Full Unlocked Without Watermark 2025," suggesting an attempt to distribute a modified version of the CapCut application, potentially to harvest Instagram credentials as part of an account‑takeover campaign.
Gridinsoft assigned a trust score of 0 out of 100, reflecting extreme malicious confidence. The domain was blocked by the PhishDestroy service and appears on a single security blocklist. VirusTotal analysis recorded a single positive detection out of 95 scanning engines, confirming at least one vendor flagged the domain as malicious. The overall risk level is classified as elevated and the campaign status is currently offline.
While the available data confirms the use of a brand‑impersonation lure and the likely distribution of a trojanized APK, the exact payload and command‑and‑control infrastructure remain unverified. Defenders should continue to monitor DNS queries for capcuteapk.com and related Cloudflare IP ranges, enforce blocklists that include the domain, and ensure that endpoints block download of unsigned APKs from untrusted sources. Network security solutions should flag HTTP traffic to the identified IP and apply URL filtering rules that capture the observed page title pattern. Incident response teams should treat any credential submissions related to Instagram from this domain as compromised and initiate account recovery procedures.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo