facebmall[.]shop
“Facebook Shop”
Зведення доказів
This domain, facebmall.shop, poses a high-risk brand impersonation threat specifically targeting Apple users. Analysis indicates the site masquerades as a legitimate Apple service, likely to harvest credentials, payment details, or deploy malicious payloads under the guise of an official platform. The page title 'Facebook Shop' is anomalous for an Apple impersonation site, suggesting either misdirection or an attempt to exploit cross-platform confusion among users. The infrastructure is designed to deceive victims into believing they are interacting with a trusted brand, increasing the likelihood of successful compromise. Evidence supporting this assessment includes detection by 22 out of 95 security vendors on VirusTotal, a clear indicator of malicious intent. The domain was registered on October 28, 2025, through Gname.com Pte. Ltd., a registrar frequently associated with high-risk domains. It resolves to the IP address 38.147.172.11, hosted under AS139659 (LUCIDACLOUD LIMITED) in Hong Kong, a network with a history of hosting phishing and fraudulent infrastructure. Google Safe Browsing has flagged the domain as phishing, and it appears on at least one security blocklist. Notably, the domain lacks an SSL certificate, further reducing its legitimacy and increasing the risk of man-in-the-middle attacks or data interception. Users who visited facebmall.shop should take immediate action to mitigate potential compromise. If credentials or payment information were entered, reset passwords for all associated accounts, enable multi-factor authentication where available, and monitor financial statements for unauthorized transactions. Scan the device used to access the site with updated security tools to detect any installed malware or backdoors. Report the incident to relevant fraud reporting platforms and consider notifying the impersonated brand (Apple) to aid in broader takedown efforts. Avoid interacting with any communications originating from this domain, including emails or messages, as they may contain further malicious links or social engineering attempts.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
Хронологія виявлення
-
Статус домену
Доступний → Недоступний
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
-
Статус домену
Недоступний → Доступний
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога