zap[.]ceo
zap.ceo için kimlik avı ve güvenlik kontrolü
“影子也有秘密👉工具箱”
zap.ceo — İçerik kullanılamıyor (HTTP 502). Marka kimliğine bürünme: Apple id; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VT 7/91 (Criminal IP, alphaMountain.ai, CRDF, Fortinet, Gridinsoft); URLQuery 0; URLScan no malicious verdict; GSB no flag; BL 1 (ScamSniffer); PD 78/100.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
zap.ceo entered the PhishDestroy evidence set on Feb 26, 2026. Stored content metadata identifies Apple id as the apparent target. Content analysis also recorded brand signals for Telegram, Tron, and Wordpress. The stored content classification is brand impersonation. The assembled evidence scores 78/100 (high).
Two independent sources are positive: VirusTotal and ScamSniffer. VirusTotal recorded 7 detections among 91 engines: Criminal IP, alphaMountain.ai, CRDF, Fortinet, Gridinsoft, Sophos, Webroot on Aug 1, 2026 at 02:21 UTC. ScamSniffer listed the hostname in the external-blocklist snapshot on Aug 7, 2026 at 18:20 UTC. The evidence is not unanimous. AlienVault OTX listed 2 community pulse references (not vendor detections) on Mar 1, 2026 at 00:35 UTC. URLQuery recorded no positive detection on Jul 12, 2025 at 23:18 UTC. Google Safe Browsing returned no flag on Mar 3, 2026 at 04:14 UTC. URLScan completed without a malicious verdict (score 0).
HTTP 502 was recorded on Aug 7, 2026 at 02:18 UTC; content was unavailable. The recorded creation date for the domain is Feb 21, 2026. Registration preceded first observation by 5 days. At collection time, the hostname resolved to 107.149.243.234 on AS398478 (PEG-HK, US). The associated network metadata labels the endpoint as AS398478 PEG TECH INC in Hong Kong, HK. The stored server header is nginx. Captured page title: “影子也有秘密👉工具箱”. DOM analysis completed on Mar 23, 2026 at 23:12 UTC; stored DOM score 78/100. The evidence archive retains 3 visual captures from PhishDestroy, URLScan, and URLQuery. IoC extraction completed on Aug 1, 2026 at 04:02 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators. TLS metadata lists R12 as the certificate issuer.
Taken together, the page content and independent findings support classifying this hostname as Apple id-themed brand impersonation.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
“@triggerpulled”
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin