MALICIOUS — CRITICAL
goump[.]cc
goump.cc was registered on June 12, 2026 through Dominet (HK) Limited.
- VirusTotal
- 16/91
- Blocklists
- No stored match
- Verfügbarkeit
- Inhalt nicht verfügbar · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
goump.cc — Inhalt nicht verfügbar (HTTP 502). Markenidentität: Govau; Betrugstyp: Impersonation. Zusammenfassung der Beweislage: VirusTotal 16/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLScan malicious verdict; PhishDestroy score 98/100. Registrar: Dominet (HK).
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
goump.cc was registered on June 12, 2026 through Dominet (HK) Limited. The domain resolves to the IPv4 address 188.114.97.3, which is currently listed on a single public security blocklist and is actively blocked by the PhishDestroy feed. VirusTotal reports that 16 of 91 scanning engines have flagged the domain as malicious, indicating a measurable level of detection across independent scanners. The available intelligence classifies the site as a generic phishing operation and assigns an elevated risk rating.
No public information about the site’s TLS certificate, HTTP response codes, page title, or associated phishing kit has been disclosed, so those aspects remain unverified. The presence on a blocklist and the multi‑engine detection suggest that the domain is being used to host phishing content, but the lack of additional technical artefacts limits a full attribution of the hosting infrastructure. Defenders should add 188.114.97.3 to their deny lists, enforce DNS sink‑hole policies for goump.cc, and monitor outbound traffic for connections to the domain.
Continuous re‑scanning on VirusTotal and inclusion in URL filtering products are recommended to capture any changes in the site’s behavior. Organizations should also consider reviewing email gateway logs for recent messages containing the domain, as the short time since registration implies a recent campaign launch. Until further forensic evidence is obtained, the domain should be treated as malicious and blocked at network perimeters.
Datenabdeckung12 recorded checks
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
VirusTotal-Analyse
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.