gulld[.]xyz
“gulld.xyz | 522: Connection timed out”
Resumen de las pruebas
The domain gulld.xyz is currently active and has been observed serving a generic phishing page that returns a 522 Connection timed out title. Registration data shows the domain was created on 16 November 2025 and is registered through Web Commerce Communications Limited. The DNS resolution points to IP 188.114.96.3, which belongs to Cloudflare, Inc. (AS13335) and is geolocated to the United States. The authoritative nameservers are anirban.ns.cloudflare.com and cass.ns.cloudflare.com, indicating the use of Cloudflare's DNS and edge services. The SSL certificate is issued by Google Trust Services under the WE1 authority, confirming that TLS termination is handled by Cloudflare.
HTTP analysis reveals a 301 redirect response, and further probing identified the presence of HTTP/3 and Cloudflare as the underlying technology stack. Reputation checks show a Gridinsoft trust score of 0 out of 100, and the domain is listed on two public blocklists. It has been flagged by the PhishDestroy and ScamSniffer filtering services. VirusTotal scans report that 6 of 95 security vendors have marked the domain as malicious, reinforcing the suspicion of phishing activity. The limited detection count suggests that some scanners have identified malicious behavior, but coverage is not exhaustive.
Uncertainty remains regarding the specific payload or credential‑stealing mechanisms hosted at the site, as the page content has not been captured beyond the generic timeout title. No additional indicators such as phishing kit fingerprints, targeted brands, or compromised credentials have been disclosed. Defenders should block outbound connections to 188.114.96.3, add gulld.xyz to URL filtering and email security policies, and monitor for any attempted communications with the domain. Continuous re‑scanning with VirusTotal or similar multi‑engine services is recommended to capture any changes in the detection landscape.
Data Coverage
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 12/08/2026
9 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
Estado del dominio
Accesible → Inaccesible
-
Cloudflare Radar
Análisis de Cloudflare Radar almacenado · Abrir análisis
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, nombres TLS y marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.