fl[.]goumad[.]cc
“goumad.cc | 520: Web server is returning an unknown error”
Resumen de las pruebas
fl.goumad.cc was registered through NameSilo, LLC on 12 June 2026 and began resolving to the address 104.21.71.34 shortly thereafter. The hosting IP belongs to a Cloudflare network used by multiple unrelated sites, which complicates attribution but does not mitigate the observed malicious activity. The domain appears on a single security blocklist and has been actively blocked by the PhishDestroy feed, indicating that at least one operational phishing detector has identified traffic associated with the domain. VirusTotal reports that 11 of 91 scanning engines have flagged the domain as malicious, a ratio that exceeds typical background noise for newly created domains and aligns with the elevated risk rating assigned by the database.
The current risk level is listed as elevated and the domain status is active, suggesting that malicious infrastructure is still reachable. The available evidence does not include a page title, SSL certificate details, HTTP response codes, or any brand‑specific lures, so the precise phishing vector cannot be confirmed at this time. Analysts should therefore treat the domain as a generic phishing platform and assume that any URLs hosted on the same IP may be used to deliver credential‑stealing pages, malicious downloads, or redirect victims to further compromised infrastructure. Defenders are advised to add 104.21.71.34 to inbound and outbound network deny lists, enforce URL filtering for the fully qualified domain name fl.goumad.cc, and monitor DNS query logs for recent resolution attempts.
Because the registrar is NameSilo, LLC, it is worthwhile to flag the registrar in any automated takedown workflow. Continued scanning with sandbox environments and periodic re‑query of VirusTotal are recommended to capture any changes in the detection score. Logging of any user‑initiated connections to the domain should be correlated with authentication failures to identify potential compromise attempts.
Data Coverage
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 12/08/2026
10 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
VirusTotal
10 → 12
-
Estado del dominio
Accesible → Inaccesible
Inteligencia de dominios
Detalles técnicosDNS, nombres TLS y marcas de tiempo
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.