tvapollogrouptv[.]com
“Apollo Group TV - Unlimited Channels, Movies & TV Shows”
tvapollogrouptv.com — Ошибка сервера (HTTP 502). Сводка доказательств: VirusTotal 2/95 (Fortinet, Gridinsoft); Spamhaus DBL_PHISH; PhishDestroy score 56/100. Регистратор: NiceNIC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
On July 24, 2026, technical analysis of tvapollogrouptv.com shows a newly registered domain created on February 22, 2026 through NiceNIC International Group Co., Limited. The domain resolves to the IPv4 address 34.111.179.208, which is allocated to Google LLC (AS396982) in the United States. No SSL certificate is presented, indicating the site operates over plain HTTP. The page title returned from the host is "Apollo Group TV - Unlimited Channels, Movies & TV Shows," suggesting an attempt to lure victims with promises of free streaming content. The domain appears on a single security blocklist and is explicitly blocked by PhishDestroy, confirming its classification as a phishing vector.
A VirusTotal scan recorded detections from 2 of 95 security vendors, providing additional corroboration of malicious intent. Current HTTP status indicates the site is offline, which may reflect a takedown or a temporary pause in operation. Nameserver records point to becky.ns.cloudflare.com and rayden.ns.cloudflare.com, typical Cloudflare DNS endpoints that do not inherently mitigate the threat. Uncertainty remains regarding the specific credential‑harvesting mechanisms or payloads because the page content has not been captured for deeper inspection.
Defenders should continue to deny traffic to tvapollogrouptv.com at network perimeters, add the domain and its IP address to internal blocklists, and monitor DNS queries for the associated Cloudflare nameservers. Ongoing surveillance of the hosting IP is advised, as shared cloud infrastructure can host both benign and malicious services. Should the domain reactivate, a full content capture is recommended to identify any form fields or malicious scripts. End‑user awareness campaigns should emphasize verification before entering login details for streaming services advertised as free or unlimited.
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-14 03:35:27 UTC
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
PD-20260222-2FC457 Recipient: abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание