apple896a32f242594befbf0a937ab758af60[.]6eqrvh[.]cn
“8dx4wy.cn | 521: Web server is down”
apple896a32f242594befbf0a937ab758af60.6eqrvh.cn — Прикритий · доступний. Уособлення бренду: Apple; Тип шахрайства: Impersonation. Зведення доказів: VirusTotal 14/91 (ADMINUSLabs, BitDefender, ESET, Forcepoint ThreatSeeker, Fortinet); Spamhaus DBL_SPAM; cloaking observed; PhishDestroy score 100/100. Реєстратор: 商中在线科技股份有限公司.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, apple896a32f242594befbf0a937ab758af60.6eqrvh.cn, poses a brand impersonation threat targeting Apple users. The site was designed to mimic legitimate Apple services, likely to harvest credentials, payment details, or distribute malware under the guise of official Apple branding. Such domains often employ convincing visuals and urgent messaging to deceive users into disclosing sensitive information or downloading malicious files. Given the domain's structure and known impersonation tactics, it represents an elevated risk to individuals unfamiliar with phishing indicators. Analysis indicates this domain was created on May 12, 2026, and is registered through 商中在线科技股份有限公司. It is flagged by 22 out of 95 security vendors on VirusTotal, suggesting broad recognition of its malicious intent. The domain resolves to the IP address 188.114.96.3, associated with CloudFlare, Inc., a common hosting provider for both legitimate and malicious sites. The SSL certificate, issued by Google Trust Services, does not validate the site's legitimacy, as certificates can be obtained for any domain. The domain appears on one security blocklist, further confirming its classification as a threat. If you visited apple896a32f242594befbf0a937ab758af60.6eqrvh.cn or interacted with its content, take immediate action to mitigate potential risks. First, disconnect the device from the network to prevent further data transmission. Run a full scan using updated antivirus or anti-malware software to detect and remove any threats. If you entered credentials, change passwords for all accounts accessed from the compromised device, prioritizing financial and email accounts. Enable multi-factor authentication where available. Monitor accounts for unauthorized activity and report any suspicious transactions to the relevant institutions. Consider resetting the device to factory settings if malware is detected or if the device exhibits unusual behavior.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога