workhomeseller[.]com
Перевірка домену workhomeseller.com на фішинг і безпеку
“Shopee”
workhomeseller.com — Контент недоступний (HTTP 502). Уособлення бренду: Apple; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 18/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); PhishDestroy score 95/100. Реєстратор: Gname.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain is flagged for elevated-risk brand impersonation targeting Apple users. Analysis indicates the infrastructure was designed to deceive victims into believing they were interacting with legitimate Apple services, likely through credential harvesting or fraudulent transaction prompts. The page title 'Shopee' suggests an attempt to mimic regional e-commerce platforms, potentially to exploit user familiarity with such interfaces while redirecting to Apple-themed fraudulent content. Infrastructure analysis reveals the domain workhomeseller.com was registered on November 06, 2025, through Gname.com Pte. Ltd., a registrar frequently associated with abusive registrations. It resolves to IP address 172.67.217.165, hosted on Cloudflare's network (AS13335), a common obfuscation tactic to mask origin servers. The domain lacks an SSL certificate, increasing the likelihood of interception or manipulation of unencrypted traffic. Security vendors on VirusTotal flagged the domain at 18/95 detections, indicating moderate consensus on its malicious nature. It appears on one security blocklist and was proactively taken offline, though historical resolution data confirms its prior operational status. Mitigation for this specific threat type involves immediate blocking of the domain and its associated IP across network security controls. Organizations should monitor for internal traffic to workhomeseller.com or similar Apple-themed impersonation domains, particularly those using Cloudflare IPs or registered through high-risk registrars like Gname.com. End-users should be educated on verifying domain legitimacy, especially for login or payment pages, and encouraged to inspect page titles and SSL certificates for inconsistencies. Given the domain's recent creation date, threat hunters should prioritize monitoring for newly registered domains with similar characteristics, including Apple-related keywords and Cloudflare hosting.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога