MALICIOUS — CRITICAL
Phishing- und Sicherheitsprüfung für fl.goumk.cc
fl[.]
fl.goumk.cc is an active generic phishing infrastructure first observed on June 12, 2026.
- VirusTotal
- 14/91
- Blocklists
- No stored match
- Verfügbarkeit
- Inhalt nicht verfügbar · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
fl.goumk.cc — Inhalt nicht verfügbar (HTTP 502). Markenidentität: Govfl; Betrugstyp: Credential Phishing. Zusammenfassung der Beweislage: VirusTotal 14/91 (ADMINUSLabs, BitDefender, CRDF, CyRadar, ESET); URLScan malicious verdict; PhishDestroy score 92/100. Registrar: Dominet (HK).
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
fl.goumk.cc is an active generic phishing infrastructure first observed on June 12, 2026. The domain resolves to the IPv6 address 2606:4700:3034::6815:1902, which is hosted by a Cloudflare edge network. Registration records show the domain was registered through Dominet (HK) Limited, a Hong Kong‑based registrar. VirusTotal reports that 14 of 91 scanned security vendors classify the domain as malicious, indicating a moderate consensus among scanners.
The domain is listed on one public security blocklist and has been explicitly blocked by the PhishDestroy feed, reinforcing its malicious reputation. The threat profile is marked as elevated risk and the campaign remains active as of the report date, July 29, 2026. Evidence beyond the registration and detection data is currently lacking; no public page title, SSL certificate details, or HTTP response information have been published. Consequently, the exact lure or target brand employed by the site cannot be confirmed at this time.
Analysts should treat the domain as a credential‑harvesting vector until more detailed forensic artifacts become available. Defenders are advised to add fl.goumk.cc to deny‑list or firewall block rules, monitor outbound connections for attempts to resolve the IPv6 address, and ensure that endpoint detection components are updated to include the 14 vendor signatures that flag the domain. Network sensors should be configured to alert on DNS queries for the domain, and any user‑initiated traffic to the associated IP should be terminated. Continuous re‑evaluation is recommended, as further intelligence such as page content or malware payloads may emerge.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Datenabdeckung12 recorded checks
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
VirusTotal-Analyse
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.