apigrokcloud[.]icu
Tóm tắt bằng chứng
This domain is flagged as a high-risk generic phishing site targeting users through fake cloud service impersonation. Analysis indicates the domain is designed to deceive visitors into entering credentials or downloading malicious payloads under the guise of legitimate cloud APIs or storage services. The threat type aligns with credential harvesting and potential secondary malware distribution, though no specific payload has been confirmed at this time. Infrastructure analysis reveals the domain apigrokcloud.icu was registered on May 13, 2026, through PDR Ltd. d/b/a PublicDomainRegistry.com, a registrar frequently associated with abusive domains. It resolves to IP address 104.21.90.237, hosted on AS13335 (Cloudflare, Inc.), a common obfuscation tactic to mask origin servers. The SSL certificate is issued by Let's Encrypt (serial E7), providing HTTPS encryption to lend false legitimacy. VirusTotal reports 15 out of 95 security vendors flagging the domain as malicious, while it appears on one security blocklist and is actively blocked by PhishDestroy. The page title 'Just a moment...' suggests the use of Cloudflare's interstitial page, further obscuring malicious content from automated scanners. Mitigation requires immediate blocking of the domain and its resolving IP (104.21.90.237) at the network perimeter. Security teams should prioritize monitoring for connections to this domain, particularly from endpoints exhibiting anomalous behavior such as unexpected credential prompts or unauthorized cloud service interactions. End-user education should emphasize verifying domain legitimacy before entering credentials, especially for cloud-based services. If credentials were entered, reset passwords immediately and enable multi-factor authentication. Network logs should be reviewed for connections to 104.21.90.237 or related subdomains of apigrokcloud.icu, with particular attention to sessions occurring after May 13, 2026.
Ảnh chụp bằng chứng đã gửi
- Đã gửi
- Bản ghi sổ cái
- 1
- Mã vụ việc
PD-20260529-22C206- Tiêu đề trang đã chụp
- Just a moment...
- Tệp PDF
- Bằng chứng PDF
Cơ sở pháp lý
Toàn văn bằng chứng
Acceptable Use Policy (AUP): The domain apigrokcloud.icu is engaged in phishing activities, which constitute a clear violation of your AUP prohibiting illegal activities, fraud, and deception.
Terms of Service (TOS): The hosting provider reserves the right to suspend or terminate services for violations, and the ongoing phishing operations associated with this domain warrant immediate action under this provision.
Applicable Laws (US):
Computer Fraud and Abuse Act (18 U.S.C. § 1030): This law prohibits unauthorized access to computers and the use of phishing schemes to defraud individuals, which is directly applicable to the activities of this domain.
CAN-SPAM Act (15 U.S.C. § 7701): This legislation regulates commercial email and prohibits deceptive practices, including phishing, which this domain is currently violating.
Wire Fraud (18 U.S.C. § 1343): The use of electronic communications to commit fraud, such as phishing, is a violation of this statute, further justifying the need for immediate action against this domain.
Regulatory Note: Failure to take prompt action against this domain may expose your organization to liability under applicable laws and regulations. Continued hosting of this phishing site could result in regulatory scrutiny and legal repercussions.
Data Coverage
Tình báo an ninh mạng
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | apigrokcloud.icu |
malicious | Sinkholed |
| DigiCert UltraDNS | apigrokcloud.icu |
malicious | Sinkholed |
| DNS4EU | apigrokcloud.icu |
malicious | Sinkholed |
| Quad9 DNS | apigrokcloud.icu |
malicious | Sinkholed |
Pipeline ứng phó với các mối đe dọa
Phạm vi danh sách chặn
10 nguồn ngoài được giám sát · ảnh chụp lưu ngày 12/08/2026
10 nguồn ngoài được giám sát Không trùng khớp
Bản chụp đã lưu
Thông tin về tên miền
Chi tiết kỹ thuậtDNS, tên TLS và mốc thời gian
VÙNG SHORTDOT · BẰNG CHỨNG CÔNG KHAI
.icu
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Bối cảnh công nhận và RAA
Bối cảnh công nhận và RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Công nghệ
Đã xác định 2 công nghệ có độ tin cậy cao
Phân tích của VirusTotal
Phân tích hiệu suất trang
Google PageSpeed Insights — mobile performance audit of apigrokcloud.icu · checked May 30, 2026
Bạn có bị ảnh hưởng bởi trang web này không?
Nếu bạn đã nhập thông tin xác thực tài khoản, thông tin cá nhân hoặc thông tin thanh toán hoặc đã tải xuống tệp từ miền này, hãy hành động ngay lập tức. Dưới đây là các nguồn lực giúp bạn báo cáo vụ việc và bảo vệ chính mình.
Hãy báo cáo với chính quyền địa phương
Chọn quốc gia của bạn để nhận liên hệ tội phạm mạng chính thức hoặc soạn thảo đơn khiếu nại →.
Kiểm tra bất kỳ tên miền nào
Phân tích mối đe dọa bằng cách sử dụng danh sách chặn được lưu trữ, WHOIS, DNS và bằng chứng quét công khai
Quét ngayBáo cáo lừa đảo qua email
Hãy gửi các tên miền đáng ngờ đến cơ sở dữ liệu mối đe dọa của chúng tôi — để bảo vệ cộng đồng
Báo cáoDòng tin tức về các mối đe dọa thời gian thực
Các báo cáo lừa đảo gần đây và những thay đổi về tính khả dụng được quan sát thấy
Theo dõiLuôn cập nhật thông tin, luôn an toàn
Theo dõi các mối đe dọa đang diễn ra hoặc phản đối danh sách này nếu bạn cho rằng đây là kết quả báo động sai