Phishing detection: icloudxtzsopoe.click
Apple Investigate
Domain
icloudxtzsopoe.click7 CT hosts on apex
IP
217.60.103.74
URL
http://icloudxtzsopoe.click/isignesp.php
Cert
YR1
Phishunt analysis Beta
34
medium suspicion suspiciousheuristic risk score · not a probability
Why?
- +5.3 Keyword match
- +4.1 Brand in screenshot
- +4.1 Site cluster
- +3.9 Password field
- +3.0 OpenPhish
- +2.2 Country mismatch
- +1.8 ASN reputation
- +1.6 Favicon (kit)
- +1.3 Suspicious TLD
- +1.1 No CSP header
- +1.1 No HSTS header
- +0.9 Young certificate
- +0.8 Young domain
- +0.7 Unrecognised DNS provider
- +0.6 Brand impersonation in path
- +0.6 Login text in screenshot
- +0.4 Long domain
- +0.3 Free CA
- +0.2 Executable page
- +0.1 External scripts
24 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting
Site impersonates Apple iCloud on a high-entropy throwaway .click domain, serving a PHP credential-harvesting page with a live password input field. Hosted on SWISSNET LLC in Switzerland and confirmed malicious by OpenPhish.
Password fieldExecutable pageOpenPhish
AI-generated from stored detector signals - the AI never visited the site. · 2026-09-16 · confidence 82%
Domain & Network
Whois
Registrar
Sav.com, LLC
Network
Country
Switzerland
Hosting
SWISSNET LLC
ASN
AS209373
TLS Cert
YR1
Requests
Resources
Observables
Related websites
Report this phishing
Submit to blocklists
urlscan
VirusTotal
Whois
ipinfo
Greynoise