fl[.]goumah[.]cc
“goumah.cc | 520: Web server is returning an unknown error”
証拠の概要
The domain fl.goumah.cc was registered on June 12, 2026 through Dominet (HK) Limited. It currently resolves to the IPv4 address 172.67.202.182, a host that is also associated with at least one public security blocklist. The domain is classified as an active generic phishing infrastructure with an elevated risk rating. VirusTotal has recorded detections from 15 of 91 scanned security vendors, indicating that a substantial minority of AV engines flag the host as malicious. Independent block‑list services have already added the domain to their deny lists; PhishDestroy specifically lists it as blocked, confirming that the domain is being actively filtered by anti‑phishing tools.
Evidence shows that the domain’s operational timeline is short, having been created only weeks before the report date of July 29, 2026. The rapid appearance of multiple vendor detections suggests that threat actors deployed the domain in a coordinated campaign rather than as a one‑off test. The lack of publicly available SSL certificate details, HTTP response codes, or page‑title information limits the ability to assess the exact payload or credential‑harvesting technique employed. Likewise, no open‑source intelligence sources such as OTX or similar have published additional indicators of compromise for this host at the time of writing.
Defenders should prioritize adding 172.67.202.182 and the fully qualified domain name fl.goumah.cc to their DNS and endpoint block lists. Monitoring for DNS queries to the domain and for outbound connections to the associated IP can help detect compromised clients. Because the domain is already listed by PhishDestroy, integrating that feed into existing web‑gateway solutions will provide immediate protection. Ongoing threat‑intel collection is recommended to capture any future changes to the hosting environment, additional payload drops, or related command‑and‑control infrastructure that may emerge as the campaign evolves.
Data Coverage
ネットワークセキュリティインテリジェンス
脅威対応 Pipeline
ブロックリストの確認範囲
監視対象の外部情報源 10 件 · 保存スナップショット 2026年8月13日
検出タイムライン
-
ドメイン状態
到達可能 → 到達不能
-
ドメイン状態
到達不能 → 到達可能
ドメイン・インテリジェンス
技術詳細DNS、TLS 名、タイムスタンプ
VirusTotalによる分析
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください