icloud[.]sa[.]com
“icloud.sa.com”
Kaydedilmiş gözlem
Gözlemlenen başlık farkı
Kanıt özeti
PhishDestroy identifies icloud.sa.com as an active brand impersonation scam targeting Apple users. The domain masquerades as iCloud to harvest credentials or deliver malicious payloads. This tactic, known as brand impersonation, is frequently used to exploit trust in recognizable brands like Apple, leading unsuspecting users to surrender sensitive login details or download malware disguised as official software.
Technical indicators reveal this domain was flagged by 12 of 95 security vendors on VirusTotal, indicating a significant but not universal consensus on its malicious nature. The domain resolves to IP 188.114.97.3 and is associated with Google Trust Services for its SSL certificate, which may lend an air of legitimacy to casual observers. The registrar remains unconfirmed in available data, and the domain has been blocked by OpenPhish and OISD, placing it on 2 security blocklists. These factors collectively highlight its elevated risk profile.
Currently, icloud.sa.com remains active and accessible, posing an ongoing threat to users who may inadvertently interact with it. Immediate action is advised: users should avoid accessing this domain and report it to their security teams or relevant authorities such as Google Safe Browsing. While multiple blocklists have flagged this domain, its persistence underscores the need for continuous monitoring and proactive threat intelligence sharing. Remaining risk is elevated due to its active status and the potential for further malicious activities, including the distribution of crypto drainers or credential theft tools.
Data Coverage
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | icloud.sa.com |
malicious | Sinkholed |
| Hagezi Threat Feed | icloud.sa.com |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 10.08.2026
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin