MALICIOUS — CRITICAL
Проверка домена goweb.network на фишинг и безопасность
goweb[.]
goweb.network is currently flagged as a generic phishing site.
- VirusTotal
- 9/93
- Blocklists
- 4 · ScamSniffer, Polkadot
- Доступность
- Контент недоступен · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
goweb.network — Контент недоступен (HTTP 502). Сводка доказательств: VirusTotal 9/93 (alphaMountain.ai, BitDefender, CyRadar, Fortinet, G-Data); 4 external blocklist matches; PhishDestroy score 82/100.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Analysis
goweb.network is currently flagged as a generic phishing site. The domain was registered on 21 February 2026 and resolves to the Cloudflare address 172.67.192.99 (AS13335, United States). TLS negotiation presents a certificate labeled WE1, which is consistent with Cloudflare‑issued certificates and does not provide a distinct brand identity. VirusTotal analysis shows that 9 of 93 scanned security vendors classify the domain as malicious, indicating a moderate level of consensus among scanners.
The domain appears on five external blocklists, including PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura, and receives a Gridinsoft trust score of 0 / 100 and a Scamadviser score of 45 / 100, both reflecting a high likelihood of abuse. The only retrieved HTTP metadata is the page title “Just a moment…”, and the service has been taken offline at the time of reporting. No additional indicators such as specific brand targets, credential‑stealing forms, or malicious payloads have been observed, so the exact phishing campaign vector remains unknown. Defenders should immediately add goweb.network to network‑level deny lists and ensure endpoint protection solutions incorporate the observed VirusTotal detections and blocklist entries.
Continuous monitoring of the IP 172.67.192.99 for new hostnames is advised, as the Cloudflare infrastructure may be reused for future campaigns. If the domain becomes active again, investigators should capture the full HTTP response, examine any redirect chains, and verify whether the TLS certificate changes. Until further evidence emerges, the domain should be treated as hostile and excluded from any allow‑list or trusted‑origin configurations.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Охват данных13 recorded checks
Процесс реагирования на угрозы
Статус в публичных блок-листах
Криминалистическая аналитика
Анализ VirusTotal
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.