mail[.]supportaccount-info[.]us
mail.supportaccount-info.us — Terselubung · dapat dijangkau. Peniruan identitas merek: Google; Jenis penipuan: Brand Impersonation. Ringkasan bukti: VirusTotal 10/91 (alphaMountain.ai, Fortinet, G-Data, Google Safebrowsing, Gridinsoft); Google Safe Browsing flagged; cloaking observed; PhishDestroy score 100/100.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
mail.supportaccount-info.us was observed hosting a brand‑impersonation campaign targeting Google users. The domain resolves to the IPv4 address 207.174.215.249, which is registered to Unified Layer (AS46606) in the United States. The hosting provider has not been publicly disclosed beyond the ASN, but the IP is listed on a single security blocklist and is flagged by Google Safe Browsing for social‑engineering content. The site was taken offline at the time of analysis, and PhishDestroy has already blocked the domain. SSL/TLS was provisioned through Let’s Encrypt with a two‑year (YR2) certificate, indicating that HTTPS was available while the site was active.
Gridinsoft assigned a trust score of 0 out of 100, reflecting a complete lack of confidence in the host’s reputation. VirusTotal reports that 10 of 91 scanned security vendors flagged the domain as malicious, corroborating the blocklist and Safe Browsing findings. The domain lacks publicly resolvable name‑server records (NS_NOT_FOUND), which may indicate deliberate obfuscation or a misconfiguration. No page title or content snapshot is available for public review, so the exact phishing landing page cannot be described.
The evidence points to a high‑risk, brand‑impersonation operation that leveraged a legitimate‑looking TLS certificate to increase credibility. Defenders should add the IP address 207.174.215.249 to network‑level deny lists, monitor DNS queries for the domain and its subdomains, and ensure that email gateways enforce strict DMARC, DKIM, and SPF checks for Google‑related communications. Continuous monitoring of the Unified Layer ASN for new malicious domains is recommended, as is sharing the indicator set with threat‑intel platforms to improve collective detection. Because the domain is currently offline, any active remediation should focus on preventing future re‑hosting of similar infrastructure.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Analisis VirusTotal
Bukti & Laporan Eksternal
PD-20260621-586F23 Recipient: abuse@publicdomainregistry.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive