workspace[.]google[.]com[.]filetransfer[.]cfd
“Index of /”
Resumo das evidências
Analysis as of July 24 2026 indicates that the domain workspace.google.com.filetransfer.cfd resolves to the IPv4 address 198.54.115.168, which is registered to AS22612 Namecheap, Inc. in the United States. The domain was registered on February 21 2026 and is currently listed as offline. VirusTotal records show that 14 of 93 security vendors have flagged the domain, confirming malicious intent. The site is classified as a Tech Support Scam that impersonates Google, and it has been added to at least one public blocklist and is actively blocked by the PhishDestroy service.
The TLS certificate presented by the host is issued by Sectigo Public Server Authentication CA DV R36, a standard domain‑validated certificate, which does not provide any indication of legitimate ownership. The only HTTP response observed prior to takedown was a generic “Index of /” page title, providing no further functional insight. The combination of brand impersonation, the tech‑support narrative, and the use of a reputable registrar’s infrastructure aligns with known patterns of credential‑harvesting campaigns targeting Google users. While the offline status limits real‑time observation, the available artifacts confirm that the domain was used to lure victims into believing they required assistance with Google services.
Uncertainty remains regarding the exact payload or phishing pages that may have been delivered, as no additional content was captured before the takedown. Defenders should continue to block both the domain and its associated IP address, propagate the indicator set to endpoint protection and web filtering solutions, and monitor for any newly registered domains that reuse the “workspace.google.com.filetransfer” sub‑domain pattern. Ongoing reconnaissance of Namecheap‑hosted infrastructure and correlation with other tech‑support scam campaigns is recommended to uncover any broader malicious infrastructure.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 10/08/2026
10 fontes externas monitoradas Sem correspondência
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ZONA SHORTDOT · EVIDÊNCIAS PÚBLICAS
.cfd
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo