cow[.]beefy-hub[.]lat
“Google”
cow.beefy-hub.lat — Контент недоступен. Олицетворение бренда: Google; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 12/95 (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar); Google Safe Browsing flagged; PhishDestroy score 86/100. Регистратор: Dynadot.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, cow.beefy-hub.lat, is flagged as a high-risk brand impersonation threat targeting Google, as indicated by its page title 'Google' and confirmed by multiple security sources. Registered on October 25, 2025, through Dynadot LLC, the domain was operational until recently taken offline. Infrastructure analysis reveals it resolved to the IP address 142.250.186.68, geolocated in Germany and associated with AS15169 (Google LLC), though this IP alignment does not confirm legitimacy and may reflect misdirection or abused hosting. No SSL certificate was detected, a common red flag for phishing infrastructure.
Detection data shows the domain appeared on one security blocklist (PhishDestroy) and was classified as social engineering by Google Safe Browsing. Twelve of 95 security vendors on VirusTotal flagged the domain, though the absence of additional context limits interpretation of these detections. The domain's trust score from Gridinsoft is 0/100, reinforcing its malicious classification. Nameservers (brenna.ns.cloudflare.com and hassan.ns.cloudflare.com) suggest Cloudflare provisioning, a frequent choice for both legitimate and malicious domains due to its privacy and performance features.
While the domain is currently offline, defenders should treat it as a confirmed phishing artifact. Historical DNS and WHOIS records should be preserved for forensic analysis, and any residual resolution attempts should be blocked. The lack of SSL, low trust scores, and blocklist presence provide sufficient evidence to classify this as a deliberate Google impersonation attempt, though the exact payload or user interaction flow remains unanalysed. No evidence links this domain to known phishing kits or broader campaigns, and further investigation would require access to archived content or logs.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Registration: beefy-hub.lat
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain beefy-hub.lat behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Криминалистическая аналитика
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание