gowtn[.]com
Pemeriksaan phishing dan keamanan gowtn.com
“WeTheNorth Marketplace - LINK 2026”
gowtn.com — Terakhir diketahui aktif (HTTP 200). Jenis penipuan: Generic Phishing. Ringkasan bukti: VirusTotal 6/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); Spamhaus DBL_PHISH; PhishDestroy score 80/100. Registrar: NiceNIC.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Evidence Analysis
The domain gowtn.com is currently active and resolves to the IPv4 address 92.42.202.100, which is registered to Noavaran System Sarv Co.Ltd in the Netherlands. The domain was created on May 09 2026 and is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, using the authoritative name servers ns3.my-ndns.com and ns4.my-ndns.com. A TLS certificate issued by Let’s Encrypt (identifier E7) is in place and the web server returns HTTP 200 for the page titled “WeTheNorth Marketplace – LINK 2026”. The site appears on one public security blocklist and is listed as blocked by PhishDestroy. VirusTotal recorded a single positive detection out of 92 scanners, and AlienVault OTX references the domain in one threat‑intelligence pulse. Gridinsoft assigned a trust score of 0 / 100, indicating a high confidence of malicious intent. While the exact phishing payload or credential‑collection mechanism has not been observed, the convergence of blocklist listings, low trust score, and a positive VirusTotal detection strongly suggest that gowtn.com is being used for generic phishing campaigns. Defenders should block the domain and its resolving IP at perimeter defenses, monitor DNS queries for the associated name servers, and consider adding the indicator to internal threat‑intel feeds.
Cakupan data12 recorded checks
Intelijen Keamanan Jaringan Registrar context
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 02:43:53 UTC
Analisis VirusTotal
Bukti & Laporan EksternalIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.