fl[.]goumad[.]cc
“goumad.cc | 520: Web server is returning an unknown error”
Résumé des preuves
fl.goumad.cc was registered through NameSilo, LLC on 12 June 2026 and began resolving to the address 104.21.71.34 shortly thereafter. The hosting IP belongs to a Cloudflare network used by multiple unrelated sites, which complicates attribution but does not mitigate the observed malicious activity. The domain appears on a single security blocklist and has been actively blocked by the PhishDestroy feed, indicating that at least one operational phishing detector has identified traffic associated with the domain. VirusTotal reports that 11 of 91 scanning engines have flagged the domain as malicious, a ratio that exceeds typical background noise for newly created domains and aligns with the elevated risk rating assigned by the database.
The current risk level is listed as elevated and the domain status is active, suggesting that malicious infrastructure is still reachable. The available evidence does not include a page title, SSL certificate details, HTTP response codes, or any brand‑specific lures, so the precise phishing vector cannot be confirmed at this time. Analysts should therefore treat the domain as a generic phishing platform and assume that any URLs hosted on the same IP may be used to deliver credential‑stealing pages, malicious downloads, or redirect victims to further compromised infrastructure. Defenders are advised to add 104.21.71.34 to inbound and outbound network deny lists, enforce URL filtering for the fully qualified domain name fl.goumad.cc, and monitor DNS query logs for recent resolution attempts.
Because the registrar is NameSilo, LLC, it is worthwhile to flag the registrar in any automated takedown workflow. Continued scanning with sandbox environments and periodic re‑query of VirusTotal are recommended to capture any changes in the detection score. Logging of any user‑initiated connections to the domain should be correlated with authentication failures to identify potential compromise attempts.
Data Coverage
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 12/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
VirusTotal
10 → 12
-
État du domaine
Accessible → Inaccessible
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif