goweb[.]network
Phishing- und Sicherheitsprüfung für goweb.network
goweb.network — Inhalt nicht verfügbar (HTTP 502). Zusammenfassung der Beweislage: VirusTotal 9/93 (alphaMountain.ai, BitDefender, CyRadar, Fortinet, G-Data); 4 external blocklist matches; PhishDestroy score 82/100.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
goweb.network is currently flagged as a generic phishing site. The domain was registered on 21 February 2026 and resolves to the Cloudflare address 172.67.192.99 (AS13335, United States). TLS negotiation presents a certificate labeled WE1, which is consistent with Cloudflare‑issued certificates and does not provide a distinct brand identity. VirusTotal analysis shows that 9 of 93 scanned security vendors classify the domain as malicious, indicating a moderate level of consensus among scanners.
The domain appears on five external blocklists, including PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura, and receives a Gridinsoft trust score of 0 / 100 and a Scamadviser score of 45 / 100, both reflecting a high likelihood of abuse. The only retrieved HTTP metadata is the page title “Just a moment…”, and the service has been taken offline at the time of reporting. No additional indicators such as specific brand targets, credential‑stealing forms, or malicious payloads have been observed, so the exact phishing campaign vector remains unknown. Defenders should immediately add goweb.network to network‑level deny lists and ensure endpoint protection solutions incorporate the observed VirusTotal detections and blocklist entries.
Continuous monitoring of the IP 172.67.192.99 for new hostnames is advised, as the Cloudflare infrastructure may be reused for future campaigns. If the domain becomes active again, investigators should capture the full HTTP response, examine any redirect chains, and verify whether the TLS certificate changes. Until further evidence emerges, the domain should be treated as hostile and excluded from any allow‑list or trusted‑origin configurations.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Forensische Erkenntnisse
VirusTotal-Analyse
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt