sir[.]magobalbontini[.]cl
“X. Alles, was gerade los ist / X”
sir.magobalbontini.cl — 未验证. 品牌冒充:Apple; 诈骗类型:Impersonation. 证据摘要: VirusTotal 14/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, Forcepoint ThreatSeeker); CF Radar malicious; PhishDestroy score 97/100. 注册商: NIC Chile.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, sir.magobalbontini.cl, poses a direct threat as a brand impersonation phishing site targeting Apple users. Visitors are likely presented with fraudulent login pages or fake promotions designed to harvest credentials, payment details, or personal information under the guise of an official Apple service. The site mimics legitimate Apple branding to deceive users into believing they are interacting with a trusted platform, increasing the risk of account compromise or financial fraud. Analysis indicates the domain was registered through NIC Chile on February 17, 2013, though its malicious use appears recent. It resolves to the IP address 162.159.140.229, hosted on Cloudflare infrastructure (AS13335), a common tactic to obscure the true origin of phishing operations. The domain is flagged by 19 out of 95 security vendors on VirusTotal, and it appears on two security blocklists: PhishDestroy and PhishingDB. Notably, the site lacks an SSL certificate, a red flag for any domain handling sensitive user data. The page title, 'X. Alles, was gerade los ist / X,' further suggests an attempt to mimic social media or trending content to lure victims. If you visited sir.magobalbontini.cl, immediate action is required to mitigate potential damage. First, disconnect the device used to access the site from any networks to prevent further data exfiltration. Run a full scan using updated security tools to detect and remove any malware or unwanted applications. Change passwords for Apple ID and any other accounts accessed from the same device, prioritizing those with financial or sensitive information. Enable multi-factor authentication where available. Monitor financial statements and credit reports for unauthorized activity, and report any suspicious transactions to your financial institution. If credentials were entered on the site, consider placing a fraud alert or credit freeze with relevant agencies. Finally, report the domain to your organization's security team or relevant authorities to aid in broader threat mitigation efforts.
安全信号
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。