tech[.]apiresolve[.]xyz
“API Reset Portal”
Kanıt özeti
PhishDestroy identifies tech.apiresolve.xyz as a credential phishing portal masquerading under the false identity of an API Reset service. The domain employs a generic but deceptive structure designed to trick users into surrendering sensitive API credentials under the pretense of resetting or reauthorizing access. The page title 'API Reset Portal' suggests official functionality, but behavioral analysis confirms malicious intent, specifically targeting authentication data from unsuspecting users. No known branded front (e.g., Microsoft, Google) is mimicked, indicating a standalone phishing operation rather than a clone of a major service.
Analysis of technical indicators reveals this domain as a high-confidence threat with 13 out of 95 VirusTotal security vendors marking it malicious as of seed 1509d3. Registered through HOSTINGER operations, UAB, the domain resolves to IP 185.232.14.243 and holds a valid Let's Encrypt SSL certificate, enhancing its credibility. The domain was created on October 11, 2025, indicating recent deployment and opportunistic targeting. Google Safe Browsing (GSB) status remains unconfirmed in public data, but third-party blocklists already flag this site, with additional detection evidence from endpoint and network security tools.
The domain remains actively accessible at the time of assessment, with no visible takedown or deactivation efforts observed. Immediate web browser and DNS-level blocking is recommended using enterprise-grade threat intelligence feeds or browser extension filters. While the overall risk is assessed as high due to active operation and low time-in-the-wild, proactive network and user-level defenses can significantly reduce exposure. Users interacting with this domain risk direct credential theft and potential downstream account compromise. Full forensic artifacts and IOCs are available in the corresponding PhishDestroy report under seed 1509d3.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260417-17604E- Yakalanan sayfa başlığı
- API Reset Portal
- PDF belgesi
- PDF kanıtı
Hukuki dayanak
Kanıtın tam metni
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | tech.apiresolve.xyz |
malicious | Sinkholed |
| DNS4EU | tech.apiresolve.xyz |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Registration: apiresolve.xyz
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For the registrable domain apiresolve.xyz behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of tech.apiresolve.xyz · checked Apr 18, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin