MALICIOUS — HIGH
flowearn[.]top
On July 24, 2026, flowearn.top was examined after being listed by PhishDestroy and appearing on a single security blocklist.
- VirusTotal
- 1/95
- Blocklists
- No stored match
- Disponibilidad
- Contenido no disponible · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
flowearn.top — Contenido no disponible (HTTP 502). Resumen de las pruebas: VirusTotal 1/95 (SOCRadar); PhishDestroy score 55/100. Registrador: NameSilo.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Evidence Analysis
On July 24, 2026, flowearn.top was examined after being listed by PhishDestroy and appearing on a single security blocklist. The domain was registered on May 20, 2025 through NameSilo, LLC and is delegated to Cloudflare nameservers gwen.ns.cloudflare.com and valentin.ns.cloudflare.com. DNS resolution points to the Cloudflare edge address 172.67.157.175, which is located in the United States and belongs to AS13335 (Cloudflare, Inc.). No TLS certificate is presented; the site served HTTP without encryption.
The only visible content retrieved before the site was taken offline was the page title “MusicEarn – Listen to Music, Earn Money,” suggesting a lure that promises monetary reward for listening to music. VirusTotal recorded a single positive detection out of 95 scanners, indicating that at least one vendor flagged the domain as malicious. The domain is currently offline, preventing further live analysis, and no additional artifacts such as login forms or tracking scripts have been observed.
Uncertainty remains regarding the full phishing kit, the targeted brand, and the exact malicious payload, as the site was not captured in a complete snapshot. Defenders should continue to block flowearn.top at network perimeter and DNS layers, monitor for any re‑hosting attempts on other Cloudflare IPs, and add the domain to internal threat‑intel feeds. Analysts are advised to watch for future registrations that reuse the same registrant or nameserver pattern, and to query threat‑sharing platforms for any emerging indicators that reference the same page title or similar reward‑based lures.
Cobertura de los datos14 recorded checks
Señales de seguridad
Inteligencia de seguridad de red Registrar context
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
Datos y informes externosIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.