apple204797a7901743bf88326c2be2d7806e[.]4fvj23[.]cn
“8dx4wy.cn | 521: Web server is down”
apple204797a7901743bf88326c2be2d7806e.4fvj23.cn — Контент недоступний. Уособлення бренду: Apple; Тип шахрайства: Impersonation. Зведення доказів: VirusTotal 20/91 (Criminal IP, BitDefender, Chong Lua Dao, Cluster25, CRDF); Spamhaus DBL_SPAM; CF Radar malicious; PhishDestroy score 95/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis confirms that the domain apple204797a7901743bf88326c2be2d7806e.4fvj23.cn is being used for brand‑impersonation targeting Apple. The site is listed on a single security blocklist and is actively blocked by PhishDestroy. It presents a valid SSL certificate issued by Google Trust Services under the WE1 intermediate, indicating that TLS termination is performed by a legitimate certificate authority. DNS resolution points to IP 188.114.96.3, an address owned by CloudFlare, Inc. and geolocated to Canada. HTTP requests receive a 301 redirect, suggesting the domain forwards traffic to another location, though the final landing page has not been captured. VirusTotal reports 20 detections out of 91 scanned vendors, reinforcing the malicious classification. The infrastructure—Google‑issued TLS, CloudFlare hosting, and the redirect behavior—is consistent with typical phishing hosting patterns. Current status is active, and the risk level is marked high. Uncertainty remains regarding the exact content served after the redirect, as no page title or content analysis is available. Defenders should immediately add the domain to block lists, monitor outbound connections to the associated IP, and enforce email filtering rules that detect Apple‑related lure patterns. Continuous re‑scanning of the IP and any new sub‑domains is recommended to capture potential shifts in the campaign’s hosting strategy.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Технології · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога