support-icloudfinds[.]us
“iCloud”
support-icloudfinds.us — 内容不可用 (HTTP 502). 品牌冒充:Apple; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 12/91 (alphaMountain.ai, Fortinet, G-Data, Gridinsoft, SOCRadar); URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 88/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, support-icloudfinds.us, poses a high-risk brand impersonation threat specifically targeting Apple users. The site mimics Apple’s iCloud login portal, designed to harvest credentials, payment details, and personal data from unsuspecting victims. Infrastructure analysis reveals the domain is engineered to exploit trust in Apple’s branding, using deceptive subdomains and visual elements identical to official Apple services. The primary objective is credential theft, which can lead to unauthorized account access, financial fraud, or further exploitation through compromised devices linked to the victim’s Apple ID. Evidence of malicious intent is substantiated by multiple technical indicators. The domain is flagged by 12 out of 95 security vendors on VirusTotal, indicating widespread detection as a phishing resource. It resolves to the IP address 207.174.215.249, hosted under AS46606 (Unified Layer) in the United States, a network frequently associated with fraudulent activities. The domain employs a Let’s Encrypt SSL certificate (YR2), which, while providing encryption, is commonly abused by threat actors to lend a false sense of legitimacy. Additionally, it appears on at least one security blocklist and is actively blocked by enterprise-grade threat intelligence platforms. The domain’s infrastructure and hosting provider further corroborate its classification as a high-risk resource. Users who have visited support-icloudfinds.us or entered credentials on the site should take immediate action to mitigate potential damage. First, revoke access to any sessions or devices linked to the compromised Apple ID via Apple’s official account recovery portal. Enable two-factor authentication (2FA) if not already active, and monitor the account for unauthorized transactions or changes. Reset passwords for any other services where the same credentials may have been reused. If financial information was entered, contact the relevant institution to report potential fraud and request account monitoring. Finally, scan the device used to access the site for malware, as phishing pages may deploy additional payloads or redirect to exploit kits. Users should report the domain to their security team or threat intelligence platforms to aid in broader mitigation efforts.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
PD-20260621-C25F32 Recipient: abuse@publicdomainregistry.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。