gwdf06x[.]xyz
“gwdf06x.xyz”
gwdf06x.xyz — Conteúdo indisponível. Resumo das evidências: VirusTotal 3/95 (Forcepoint ThreatSeeker, Gridinsoft, Trustwave); PhishDestroy score 65/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain gwdf06x.xyz was registered on 21 February 2026 and is currently listed as offline. The sole page title returned by the server is “gwdf06x.xyz”, indicating no additional branding or targeted victim information. DNS resolution points to the IPv4 address 76.223.26.96, which is allocated to Amazon Web Services (AS16509, Amazon.com, Inc.) and geolocated to the United States. An SSL certificate identified as “R11” is present, confirming the use of Transport Layer Security but providing no further validation of ownership. VirusTotal analysis shows that three out of ninety‑five scanners flagged the domain, suggesting the presence of malicious components, although the specific nature of the detections was not disclosed.
Independent threat‑intelligence feeds have placed the domain on a single security blocklist, and the PhishDestroy service has actively blocked access to it. No additional public blocklists or safe‑browsing entries were reported. The limited data set prevents definitive attribution of the phishing campaign’s target or payload. Absence of a visible login form, brand name, or credential‑harvesting page in the available metadata means that investigators cannot confirm whether the site was used to harvest credentials, deliver malware, or perform other fraudulent actions. Consequently, the primary uncertainty concerns the exact phishing technique employed and any associated victim demographics.
Defenders should continue to monitor the IP address 76.223.26.96 for any re‑use in future malicious deployments, especially given its association with a cloud provider that can be rapidly provisioned. Network security controls such as DNS sinkholing or URL filtering should be updated to include gwdf06x.xyz and its resolved IP. Organizations employing threat‑intelligence platforms should flag the domain as malicious and correlate any internal alerts that reference the same IP or ASN.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo