white-whale-v3[.]live
“Google”
white-whale-v3.live — Contenu indisponible (HTTP 502). Usurpation de l'identité de la marque : Google; Type d'arnaque : Generic Phishing. Résumé des preuves: VirusTotal 5/93 (alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); PhishDestroy score 65/100.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
The domain white-whale-v3.live was observed resolving to the IPv4 address 172.253.139.147, which belongs to AS15169 Google LLC and is geolocated in the United States. The domain is delegated to the Cloudflare nameservers mona.ns.cloudflare.com and rudy.ns.cloudflare.com, a configuration frequently seen in fast‑flux or abuse‑resistant hosting. No TLS certificate was presented during connection attempts, indicating that the site served only HTTP content. The page title returned by the server was the literal string “Google”, matching the declared brand target of Google and confirming a brand‑impersonation intent.
VirusTotal recorded five positive detections out of ninety‑three submitted scanners, and the domain appears on a single external blocklist that is actively enforced by the PhishDestroy service. The site has been taken offline as of the report date, July 22 2026, but the infrastructure artifacts remain observable. The combination of a legitimate‑looking IP address, Cloudflare DNS, and the absence of encryption suggests an attempt to exploit user trust in Google’s network while avoiding the overhead of certificate procurement. At present, no additional forensic artefacts such as payload samples, login forms, or redirects have been published, leaving the exact phishing workflow unknown.
Further analysis is required to determine whether the site hosted credential‑stealing forms or redirected victims to a downstream command‑and‑control server. Defensive recommendations include adding the domain and its resolving IP to network‑level deny lists, monitoring for new subdomains under the same nameserver pair, and ensuring that web filtering solutions flag any HTTP response whose title equals “Google” when the host does not belong to Google’s official certificate authority. Continuous re‑query of VirusTotal and blocklist feeds is advised to capture any emerging detections.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse VirusTotal
Preuves archivées
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif