apple5a277ebfbad8462c9c6d0f2380520d41[.]5eg94f[.]cn
“8dx4wy.cn | 521: Web server is down”
apple5a277ebfbad8462c9c6d0f2380520d41.5eg94f.cn — Непроверенный. Олицетворение бренда: Apple; Тип мошенничества: Impersonation. Сводка доказательств: VirusTotal 16/91 (BitDefender, Chong Lua Dao, Cluster25, CRDF, ESET); Spamhaus DBL_SPAM; CF Radar malicious; PhishDestroy score 95/100.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis as of July 19 2026 indicates that the domain apple5a277ebfbad8462c9c6d0f2380520d41.5eg94f.cn, observed as 5eg94f.cn, is being used for a high‑risk Apple brand‑impersonation campaign. The site returns an HTTP 301 redirect and presents a TLS certificate issued by Google Trust Services under the WE1 intermediate, confirming that the connection is encrypted but does not validate the legitimacy of the host. Infrastructure traces show the hostname resolves to 104.21.47.240, an address owned by Cloudflare, Inc. and geolocated to Canada. The domain has been added to a single security blocklist and is already blocked by the PhishDestroy feed. VirusTotal reports 11 of 91 scanners flagging the domain, reinforcing the malicious assessment. The available intelligence does not disclose the exact payload, landing page content, or phishing kit employed, so the full attack vector remains unknown. Defenders should add the domain and its resolved IP to outbound‑allow and DNS‑sinkhole rules, monitor TLS handshake anomalies for the Google Trust Services certificate, and ensure that any user‑initiated connections to the domain are blocked at the firewall or proxy level. Continuous re‑evaluation is advised, as the active status and the presence of a redirect suggest the operator may alter the payload or host new malicious content at any time.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
Технологии · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание