MALICIOUS — CRITICAL
graphql-m2[.]snowdog[.]dev
PhishDestroy identifies graphql-m2.snowdog.dev as an active phishing domain engineered to mimic a legitimate GraphQL interface, primarily targeting developers and technical users with sophisticated spoofing tactics.
- VirusTotal
- 14/91
- Blocklists
- No stored match
- Disponibilité
- Contenu indisponible · HTTP 503
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
graphql-m2.snowdog.dev — Contenu indisponible (HTTP 503). Type d'arnaque : Credential Phishing. Résumé des preuves: VirusTotal 14/91 (BitDefender, Chong Lua Dao, CRDF, CyRadar, ESET); PhishDestroy score 92/100. Bureau d’enregistrement: OVH sas.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Evidence Analysis
PhishDestroy identifies graphql-m2.snowdog.dev as an active phishing domain engineered to mimic a legitimate GraphQL interface, primarily targeting developers and technical users with sophisticated spoofing tactics. This domain resolves to the IP address 104.21.21.152 and is currently protected by a Google Trust Services SSL certificate, which lends false legitimacy to its fraudulent pages. The domain was flagged with a unique seed identifier 07b1f4 and remains under investigation for active phishing operations.
This domain exhibits clear indicators of compromise: VirusTotal currently reports 1 out of 95 antivirus engines detecting the threat, highlighting the evasive nature of the campaign. The domain leverages a deceptive naming convention to appear connected to the legitimate service snowdog.dev, potentially exploiting user trust in well-known developer tools. The infrastructure maps to Cloudflare IP ranges, commonly abused for phishing operations due to their global distribution and caching capabilities.
Users who may have visited graphql-m2.snowdog.dev should immediately review browser history and disable any active sessions on developer platforms or email accounts accessed from that session. Change passwords immediately, especially for accounts linked to development tools or API access. Enable multi-factor authentication wherever possible, and report the domain to your IT security team or via PhishDestroy’s submission portal. Consider using a reputable DNS filtering service to block future access to this malicious domain.
Couverture des données12 recorded checks
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
ICANN OVERSIGHT
Registration: snowdog.dev
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain snowdog.dev behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of graphql-m2.snowdog.dev · checked May 17, 2026
Données factuelles et rapports externesIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.