goumvco[.]cc
“goumvco.cc | 520: Web server is returning an unknown error”
goumvco.cc — Não verificado. Representação da marca: Govfl; Tipo de golpe: Impersonation. Resumo das evidências: VirusTotal 16/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLScan malicious verdict; PhishDestroy score 95/100. Registrador: Dominet (HK).
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
goumvco.cc was registered on June 12, 2026 through Dominet (HK) Limited. The domain currently resolves to the IPv4 address 172.67.185.109. VirusTotal reports that 16 of 91 scanned security vendors flag the domain, indicating a moderate level of detection across the community. The domain appears on a single public blocklist and is specifically listed by the PhishDestroy service, confirming its classification as a malicious phishing resource. The campaign is labeled as generic phishing and assigned an elevated risk rating.
The domain remains active as of the report date, July 29, 2026. Analysis of the available telemetry suggests that the threat actor leveraged a recently created domain to host a phishing payload, relying on fast‑flux hosting or CDN services to obscure the underlying infrastructure. The limited blocklist presence may reflect a short operational window, but the multi‑vendor detections demonstrate that multiple security products have identified malicious activity associated with the host. No additional intelligence such as SSL certificate details, HTTP response codes, or page title is currently available. Defenders should prioritize immediate containment measures.
Adding goumvco.cc to outbound URL filtering rules, DNS sinkhole configurations, and endpoint web‑proxy block lists will prevent user access. Network security devices should also block traffic to 172.67.185.109, while monitoring for any subsequent resolution changes. Continuous re‑query of VirusTotal and other reputation services is advised to capture evolving detection counts. Organizations employing email security gateways should update phishing signatures to include the domain and its associated indicators of compromise. Ongoing threat‑intel sharing with peers will aid in tracking potential expansion of the campaign.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo