gom-player[.]app
“GOM Player - Professional Media Player for Windows | Free Download”
Resumo das evidências
This domain, gom-player.app, is a fraudulent website designed to distribute malware under the guise of offering a free download of GOM Player, a legitimate media player for Windows. Users visiting the site are presented with a convincing replica of the official GOM Player website, complete with identical branding, layout, and download prompts. The site exploits the trust associated with the GOM Player name to trick users into downloading malicious software, which may include trojans, ransomware, or other forms of malware. The threat posed by this site extends beyond individual users, as compromised systems can be leveraged for further malicious activities, including data exfiltration, botnet recruitment, or lateral movement within a network. Analysis indicates that gom-player.app was registered on January 10, 2026, through Spaceship, Inc., a domain registrar that has been associated with other malicious infrastructure in the past. Despite its recent creation, the site has already been flagged by one security blocklist and is actively blocked by Maltrail, a network-based threat detection system. Notably, the domain currently resolves to the IP address 188.114.96.3 and uses a Let's Encrypt SSL certificate to present a false sense of security. VirusTotal analysis reveals zero detections out of 95 security engines (0/95), suggesting that the malware being distributed may be novel or obfuscated to evade detection. The lack of detections underscores the importance of proactive monitoring, as traditional signature-based defenses may not yet recognize the threat. If you or someone in your organization has visited gom-player.app or downloaded files from the site, immediate action is required to mitigate potential risks. First, disconnect the affected device from the network to prevent further data loss or lateral spread of malware. Do not interact with any downloaded files or execute any programs from the site. Perform a full system scan using updated antivirus or endpoint detection and response (EDR) tools to identify and remove any malicious payloads. If malware is detected, consider restoring the system from a known clean backup or performing a clean installation of the operating system. Additionally, monitor network traffic for unusual outbound connections, particularly to the IP address 188.114.96.3, and review logs for signs of compromise. Users should also reset passwords for any accounts accessed from the compromised device, especially if those credentials may have been exposed. Finally, report the domain to relevant security teams or threat intelligence platforms to aid in broader detection and takedown efforts.
Instantâneo das evidências enviadas
- Enviado
- Registros do livro-razão
- 1
- ID do caso
PD-20260702-F105B1- Título da página capturada
- GOM Player - Professional Media Player for Windows | Free Download
- Artefato PDF
- Evidência em PDF
Base jurídica
Texto completo da evidência
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologias
6 tecnologias identificadas com alta confiança
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of gom-player.app · checked Jul 2, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo