spotifyapk[.]co
“Spotify Premium APK v9.1.14.864 Download January 2026”
已存储的观测记录
观测到的标题差异
证据摘要
Analysis of the domain spotifyapk.co, created on February 21 2026 and hosted behind Cloudflare (ASN 13335, United States), shows an active generic phishing campaign targeting users seeking a Spotify Premium APK. The site returns an HTTP 301 redirect and presents a page titled “Spotify Premium APK v9.1.14.864 Download January 2026.” The SSL certificate is issued by Google Trust Services under the WE1 designation, indicating a valid TLS handshake despite the malicious intent. Technical fingerprints reveal a WordPress stack backed by MySQL and PHP, with auxiliary services including YouTube embeds, Cloudflare Browser Insights, and HTTP/3 enabled. DNS resolution points to IP 188.114.96.3, consistent with Cloudflare’s edge network.
Reputation data shows that 15 of 93 VirusTotal scanners flag the domain, and it appears on three independent blocklists, currently blocked by PhishDestroy, MetaMask, and SEAL. The registrar is GoDaddy.com, LLC, and the authoritative nameservers are sneh.ns.cloudflare.com and sullivan.ns.cloudflare.com. Gridinsoft assigns a trust score of 1 out of 100, reflecting extreme risk.
While the page title confirms the lure of a counterfeit Spotify APK, no additional payload samples or credential‑harvesting forms have been publicly disclosed. Defenders should immediately block both the domain and its resolving IP at network perimeters, update web‑filtering rules, and monitor for related C2 traffic using the observed Cloudflare infrastructure. Continuous re‑scanning of the site is advised, as the low trust score and multi‑vendor detections suggest that the infrastructure may evolve or host additional malicious artifacts.
Data Coverage
安全信号
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
检测时间线
-
Cloudflare Radar
已存储 Cloudflare Radar 扫描 · 打开扫描
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of spotifyapk.co · checked Mar 2, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控