gov-dwpqos[.]top
Analysis indicates that the domain gov-dwpqos.top was registered through 阿里云计算有限公司 on June 12, 2026. The domain is currently flagged by multiple security services; PhishDestroy has placed it on its blocklist, and it appears on an additional security blocklist, giving a total of one external blocklist entry. VirusTotal scans show that 15 of 91 vendors have generated a detection for the domain, confirming a consensus that the site is associated with malicious activity. The limited number of blocklist entries suggests that the domain may be newly active, consistent with its recent registration date.
The available intelligence does not provide details about the hosting IP address, ASN, or geographic location, leaving the underlying infrastructure uncharacterized. Likewise, no information about SSL certificates, HTTP response codes, or page titles has been disclosed, preventing a deeper assessment of the site’s content or its delivery mechanisms. The absence of these data points means that defenders cannot attribute the domain to a specific phishing kit or confirm whether the site is currently serving payloads. Given the confirmed detections by a substantial subset of VirusTotal scanners and the explicit block by PhishDestroy, defensive teams should treat the domain as hostile.
Recommended actions include adding the domain to proxy and firewall deny lists, configuring web filtering solutions to block any HTTP/HTTPS requests to the hostname, and monitoring DNS logs for queries to the domain. Organizations should also consider sharing the indicator with threat‑sharing communities to improve collective visibility. Continuous re‑evaluation is advised, as further scanning may reveal additional infrastructure details or changes in detection status.
Network Security Intelligence
Threat Response Pipeline
Public Blocklist Status
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive