mail[.]findmy-app[.]us
“iCloud”
mail.findmy-app.us — Прикритий · доступний. Уособлення бренду: Apple. Зведення доказів: VirusTotal 15/94 (ADMINUSLabs, alphaMountain.ai, Chong Lua Dao, Cluster25, CRDF); URLQuery 2 alerts; URLScan malicious verdict; cloaking observed; PhishDestroy score 95/100. Реєстратор: NameSilo.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, mail.findmy-app.us, is identified as a credential harvesting phishing site designed to capture user login credentials through deceptive login portals. Analysis indicates no direct association with a specific brand impersonation or cryptocurrency drainer kit, though the infrastructure aligns with generic phishing campaigns targeting authentication credentials. The lack of a recognized brand impersonation suggests a broader, opportunistic approach rather than a targeted campaign against a single entity. Infrastructure analysis reveals the following technical indicators: the domain resolves to IP address 199.79.63.68, hosted in the United States under provider PDR. It was registered on March 24, 2026, through NameSilo, LLC, a registrar frequently observed in phishing operations due to its accessibility and low-cost domain registration services. The domain lacks an SSL certificate, increasing its detectability as malicious. VirusTotal reports 15 out of 95 security vendors flagging the domain as malicious, while it appears on one additional security blocklist. Google Safe Browsing (GSB) does not currently list the domain, though this may reflect a lag in detection rather than benign status. As of the latest assessment, mail.findmy-app.us has been taken offline, likely in response to detection by security mechanisms. However, the domain remains registered, posing a residual risk of reactivation or repurposing for future malicious activity. Organizations and individuals are advised to block the domain at the DNS or proxy level to prevent accidental exposure. Users who may have interacted with the site should reset credentials for any accounts entered on the portal and monitor for unauthorized access. Given the domain's registration through a low-friction provider, continuous monitoring for re-emergence is recommended.
Розвіддані з мережевої безпеки Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | mail.findmy-app.us |
phishing | Phishing Block |
| Hagezi Threat Feed | mail.findmy-app.us |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
PD-20260324-23001A Recipient: abuse@publicdomainregistry.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога