khocert.click
Appeared in the .click zone on Friday, August 28, 2026; by the end of that day the census found active website. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
Vietnamese storefront selling Apple P12/mobileprovision signing certificates by UDID for sideloading modified/pirated apps and 'unbanning' blacklisted devices, with Telegram operator contact — a grey-market abuse of Apple developer certificates enabling app piracy, not an impersonation of Apple (site brands itself KHOCERT.CLICK).
The site sells Apple P12 certificates and provisioning profiles to bypass Apple's security controls and sideload applications without jailbreak, enabling unauthorized app distribution. This is abuse of Apple's infrastructure for counterfeit/unauthorized certificate provisioning, not phishing—the domain does not impersonate Apple's login or portal, but operates as an unlicensed certificate reseller facilitating platform abuse.
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Friday, August 28, 2026

Same data as JSON: /api/zone/domain/khocert.click. This page is not indexed by search engines and does not link to the site it describes.