mail[.]supportaccount-info[.]us
mail.supportaccount-info.us — مغطى بعباءة · يمكن الوصول إليه. انتحال العلامة التجارية: Google; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 10/91 (alphaMountain.ai, Fortinet, G-Data, Google Safebrowsing, Gridinsoft); Google Safe Browsing flagged; cloaking observed; PhishDestroy score 100/100.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
mail.supportaccount-info.us was observed hosting a brand‑impersonation campaign targeting Google users. The domain resolves to the IPv4 address 207.174.215.249, which is registered to Unified Layer (AS46606) in the United States. The hosting provider has not been publicly disclosed beyond the ASN, but the IP is listed on a single security blocklist and is flagged by Google Safe Browsing for social‑engineering content. The site was taken offline at the time of analysis, and PhishDestroy has already blocked the domain. SSL/TLS was provisioned through Let’s Encrypt with a two‑year (YR2) certificate, indicating that HTTPS was available while the site was active.
Gridinsoft assigned a trust score of 0 out of 100, reflecting a complete lack of confidence in the host’s reputation. VirusTotal reports that 10 of 91 scanned security vendors flagged the domain as malicious, corroborating the blocklist and Safe Browsing findings. The domain lacks publicly resolvable name‑server records (NS_NOT_FOUND), which may indicate deliberate obfuscation or a misconfiguration. No page title or content snapshot is available for public review, so the exact phishing landing page cannot be described.
The evidence points to a high‑risk, brand‑impersonation operation that leveraged a legitimate‑looking TLS certificate to increase credibility. Defenders should add the IP address 207.174.215.249 to network‑level deny lists, monitor DNS queries for the domain and its subdomains, and ensure that email gateways enforce strict DMARC, DKIM, and SPF checks for Google‑related communications. Continuous monitoring of the Unified Layer ASN for new malicious domains is recommended, as is sharing the indicator set with threat‑intel platforms to improve collective detection. Because the domain is currently offline, any active remediation should focus on preventing future re‑hosting of similar infrastructure.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة والتقارير الخارجية
PD-20260621-586F23 Recipient: abuse@publicdomainregistry.com هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب