zwzmkgrzwr[.]yoga
“Facebook Shop”
zwzmkgrzwr.yoga — Контент недоступен (HTTP 502). Олицетворение бренда: Apple; Тип мошенничества: Tech Support Scam. Сводка доказательств: VirusTotal 18/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, Cluster25, CRDF); URLQuery 4 alerts; URLScan malicious verdict; PhishDestroy score 95/100. Регистратор: NameSilo.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain is flagged for elevated-risk brand impersonation targeting Apple Inc. through a fraudulent storefront labeled 'Facebook Shop.' The threat type involves deceptive credential harvesting, where victims are lured into entering sensitive account information under the pretense of accessing Apple services or promotions. The domain’s infrastructure and rapid detection by security systems indicate a deliberate attempt to exploit trust in the targeted brand, posing significant risks to user data integrity and financial security.
Analysis reveals the domain zwzmkgrzwr.yoga was registered on July 31, 2025, through NameSilo, LLC, a registrar frequently associated with abusive domains. It resolves to the IP address 45.204.212.94, hosted under AS62468 (VpsQuan L.L.C.) in Hong Kong, a network segment with a history of malicious activity. The domain appears on one security blocklist (PhishDestroy) and is detected by 18 out of 95 security vendors on VirusTotal, reflecting moderate to high confidence in its malicious nature. The SSL certificate (R12) is issued by a non-extended validation provider, further reducing trustworthiness. The page title 'Facebook Shop' suggests an attempt to mimic social commerce platforms, likely to bypass initial user skepticism.
Mitigation requires immediate action from both users and network defenders. Users who encountered this domain should reset credentials for any accounts accessed during the interaction, particularly Apple IDs, and enable multi-factor authentication where available. Network administrators are advised to block the domain and its resolving IP (45.204.212.94) at the perimeter, while monitoring for related indicators of compromise, such as unusual login attempts or phishing emails referencing Apple or Facebook services. Organizations should also review registrar policies for domains created under NameSilo, LLC, and assess the risk of similar impersonation attempts targeting their brand. Proactive threat hunting for domains with similar naming patterns (e.g., random character strings followed by .yoga) can help identify emerging campaigns.
Данные сетевой безопасности Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | zwzmkgrzwr.yoga |
malicious | Sinkholed |
| DigiCert UltraDNS | zwzmkgrzwr.yoga |
malicious | Sinkholed |
| DNS4EU | zwzmkgrzwr.yoga |
malicious | Sinkholed |
| Quad9 DNS | zwzmkgrzwr.yoga |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание