google8989[.]top
“购物 - 好叭工作室”
Зведення доказів
Analysis of the domain google8989.top indicates it was actively used for a tech support scam impersonating Google, as classified in available threat intelligence. The domain was registered on March 3, 2026, through NameSilo, LLC, and resolved to the IP address 45.207.215.172, hosted by AS401696 (cognetcloud INC) in Hong Kong. The page title retrieved from the site was '购物 - 好叭工作室', which does not directly reference Google but aligns with broader fraudulent activity patterns observed in brand impersonation schemes. No SSL certificate was detected, increasing the likelihood of unencrypted data transmission.
The domain appeared on three security blocklists and was flagged by at least one of 94 security vendors on VirusTotal, though the specific detection context remains unverified. It was blocked by PhishDestroy, MetaMask, and SEAL, suggesting recognition as malicious infrastructure. The nameservers (ns1.dnsowl.com, ns2.dnsowl.com, ns3.dnsowl.com) are consistent with those used in other phishing operations, though this alone does not confirm intent. As of July 22, 2026, the domain is offline, limiting further analysis of its operational behavior.
Defenders should treat this domain as part of a historical tech support scam campaign targeting Google users. Network-level blocking of the IP 45.207.215.172 and associated nameservers may mitigate residual risk from related infrastructure. No evidence suggests this domain was part of a larger phishing kit or hosted additional malicious payloads, but monitoring for re-registration or similar naming conventions (e.g., 'google' followed by numeric sequences) is recommended.
Знімок надісланих доказів
- Надіслано
- Записи журналу
- 1
- ID справи
PD-20260303-A327AB- Заголовок збереженої сторінки
- 购物 - 好叭工作室
- PDF-файл
- PDF із доказами
Правова підстава
Повний текст доказів
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (US):
18 U.S.C. § 1343 - Wire Fraud
18 U.S.C. § 1030 - Computer Fraud and Abuse Act (CFAA)
15 U.S.C. § 45 - FTC Act (Deceptive Practices)
Federal laws prohibit wire fraud, computer fraud, and deceptive business practices.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
8 зовнішніх джерел під наглядом Збігів немає
Хронологія виявлення
-
VirusTotal
0 → 1
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
-
Статус домену
Доступний → Недоступний
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of google8989.top · checked Mar 3, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога