sspl[.]com[.]auaumail7[.]sspl[.]com[.]aumail7[.]sspl[.]com[.]au
“Index of /”
sspl.com.auaumail7.sspl.com.aumail7.sspl.com.au — Non vérifié. Usurpation de l'identité de la marque : Google; Type d'arnaque : Impersonation. Résumé des preuves: VirusTotal 16/91 (AILabs (MONITORAPP), BitDefender, Cluster25, CyRadar, ESET); Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 98/100. Bureau d’enregistrement: Web Address Registrati….
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis of sspl.com.auaumail7.sspl.com.aumail7.sspl.com.au shows multiple indicators of malicious activity targeting the Google brand. The site returned an HTTP 200 response with the page title "Index of /", a generic directory listing that offers no legitimate content. DNS resolution points to the IP address 185.184.154.169, which is registered to Dreamscape Networks Limited (AS38719) in Australia. The domain is registered through Web Address Registration Pty Ltd and uses three Vodien nameservers (ns1.vodien.com, ns2.vodien.com, ns3.vodien.com).
A Let’s Encrypt R12 certificate was observed, indicating the presence of TLS but offering no authentication of the site owner. Google Safe Browsing flags the URL for social engineering, and the domain appears on one security blocklist. VirusTotal recorded 15 detections out of 95 scanned vendors, reinforcing the suspicion of abuse. Additional telemetry includes a Gridinsoft trust score of 0 out of 100 and a block entry from PhishDestroy.
The infrastructure is currently offline, but the historical evidence suggests the domain was used to impersonate Google, likely as part of a credential‑harvesting campaign. Uncertainty remains regarding the exact payload or phishing kit employed, as no page content beyond the directory index has been captured. Defenders should continue to block the domain at network perimeter devices, update URL filtering and threat‑intel feeds with the observed indicators, and monitor the associated IP and nameserver infrastructure for any re‑activation. Incident response teams encountering traffic to this host should treat it as malicious, isolate affected endpoints, and enforce credential resets for any Google accounts potentially exposed.
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse VirusTotal
Preuves archivées
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of sspl.com.auaumail7.sspl.com.aumail7.sspl.com.au · checked Mar 2, 2026
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif