w[.]beefyhubs[.]monster
“Google”
The domain w.beefyhubs.monster was observed with a creation timestamp of 26 Oct 2025 and is registered through Dynadot LLC. DNS resolution is delegated to brenna.ns.cloudflare.com and hassan.ns.cloudflare.com, both Cloudflare name servers. A lookup resolves the hostname to 142.251.140.164, an address owned by Google LLC (AS15169) located in the United States. The HTTP response returns a page whose title is "Google", matching the declared brand target of Google and confirming the intent to impersonate that brand. No TLS certificate was presented during the connection, indicating an unencrypted service.
VirusTotal records show that 11 of 95 scanning engines flag the domain as malicious, and the domain appears on a single external blocklist, where it has been listed by PhishDestroy. The site is currently taken offline, and no further content has been captured. Evidence suggests a brand‑impersonation campaign that leverages a legitimate Google IP range to increase credibility.
Because the service lacks TLS, interception is trivial, but the use of a Google‑owned address may bypass some reputation filters. Defenders should block the domain at the network perimeter, monitor the associated IP for additional malicious activity, and consider adding the name servers to watchlists. Ongoing surveillance of DNS changes, rapid removal from resolve caches, and updating threat intelligence platforms to retain historical indicators are recommended until the threat is fully mitigated.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Registration: beefyhubs.monster
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For the registrable domain beefyhubs.monster behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive