# PhishDestroy threat dossier — gom-player.app ================================================================ Fetched: 2026-07-03 03:14:13 UTC Canonical: https://phishdestroy.io/domain/gom-player.app/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 19/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar, ESET, ESTsecurity, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Kaspersky, Lionic, Seclookup, SOCRadar, Sophos, Viettel Threat Intelligence, VIPRE URLQuery: 2 detections AlienVault OTX: 1 pulses (threat-intel feed mentions) Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.96.3 (US, San Francisco) Hosting org: AS13335 Cloudflare, Inc. Registrar: Spaceship, Inc. Nameservers: clay.ns.cloudflare.com, marge.ns.cloudflare.com Registered: 2026-01-10 Expires: 2027-01-10 Page title: GOM Player - Professional Media Player for Windows | Free Download ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E8 Expires: 2026-08-23 Status: INVALID chain Fingerprint: 6d9dce2a0f08469333424ac23775e1386ad7b9644f6add988e3dc902d545691c ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-01-10 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-02 14:42:21 UTC (by PhishDestroy tracker) First reported: 2026-07-02 12:47:21 UTC (abuse notice filed) Last verified: 2026-07-03 04:20:37 UTC Neutralised: 2026-07-03 03:02:48 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f22d8-9fc7-72c9-b00c-e460e630c0ec/ URLQuery: https://urlquery.net/report/62ffc557-4de9-43bd-9d7e-0511d6411d99 Wayback Machine: https://web.archive.org/web/*/gom-player.app crt.sh CT logs: https://crt.sh/?q=%25.gom-player.app Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=gom-player.app AlienVault OTX: https://otx.alienvault.com/indicator/domain/gom-player.app URLhaus: https://urlhaus.abuse.ch/host/gom-player.app/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-02 14:46:09 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] This domain, gom-player.app, is a fraudulent website designed to distribute malware under the guise of offering a free download of GOM Player, a legitimate media player for Windows. Users visiting the site are presented with a convincing replica of the official GOM Player website, complete with identical branding, layout, and download prompts. The site exploits the trust associated with the GOM Player name to trick users into downloading malicious software, which may include trojans, ransomware, or other forms of malware. The threat posed by this site extends beyond individual users, as compromised systems can be leveraged for further malicious activities, including data exfiltration, botnet recruitment, or lateral movement within a network. Analysis indicates that gom-player.app was registered on January 10, 2026, through Spaceship, Inc., a domain registrar that has been associated with other malicious infrastructure in the past. Despite its recent creation, the site has already been flagged by one security blocklist and is actively blocked by Maltrail, a network-based threat detection system. Notably, the domain currently resolves to the IP address 188.114.96.3 and uses a Let's Encrypt SSL certificate to present a false sense of security. VirusTotal analysis reveals zero detections out of 95 security engines (0/95), suggesting that the malware being distributed may be novel or obfuscated to evade detection. The lack of detections underscores the importance of proactive monitoring, as traditional signature-based defenses may not yet recognize the threat. If you or someone in your organization has visited gom-player.app or downloaded files from the site, immediate action is required to mitigate potential risks. First, disconnect the affected device from the network to prevent further data loss or lateral spread of malware. Do not interact with any downloaded files or execute any programs from the site. Perform a full system scan using updated antivirus or endpoint detection and response (EDR) tools to identify and remove any malicious payloads. If malware is detected, consider restoring the system from a known clean backup or performing a clean installation of the operating system. Additionally, monitor network traffic for unusual outbound connections, particularly to the IP address 188.114.96.3, and review logs for signs of compromise. Users should also reset passwords for any accounts accessed from the compromised device, especially if those credentials may have been exposed. Finally, report the domain to relevant security teams or threat intelligence platforms to aid in broader detection and takedown efforts. [Updates since narrative was generated:] - VirusTotal detections: now 19/91 (narrative was written when count was lower) ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260702-F105B1 Favicon MD5: be080a0b77fd32c61d5dfd72d1d03ff1 TLS cert SHA-256: 6d9dce2a0f08469333424ac23775e1386ad7b9644f6add988e3dc902d545691c ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/gom-player.app/ JSON API: https://api.destroy.tools/v1/check?domain=gom-player.app Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 174,112 domains (13,934 alive under monitoring, 159,389 confirmed takedowns/dead). Site: https://phishdestroy.io