mail[.]supportaccount-info[.]us
mail.supportaccount-info.us — Прикритий · доступний. Уособлення бренду: Google; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 10/91 (alphaMountain.ai, Fortinet, G-Data, Google Safebrowsing, Gridinsoft); Google Safe Browsing flagged; cloaking observed; PhishDestroy score 100/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
mail.supportaccount-info.us was observed hosting a brand‑impersonation campaign targeting Google users. The domain resolves to the IPv4 address 207.174.215.249, which is registered to Unified Layer (AS46606) in the United States. The hosting provider has not been publicly disclosed beyond the ASN, but the IP is listed on a single security blocklist and is flagged by Google Safe Browsing for social‑engineering content. The site was taken offline at the time of analysis, and PhishDestroy has already blocked the domain. SSL/TLS was provisioned through Let’s Encrypt with a two‑year (YR2) certificate, indicating that HTTPS was available while the site was active.
Gridinsoft assigned a trust score of 0 out of 100, reflecting a complete lack of confidence in the host’s reputation. VirusTotal reports that 10 of 91 scanned security vendors flagged the domain as malicious, corroborating the blocklist and Safe Browsing findings. The domain lacks publicly resolvable name‑server records (NS_NOT_FOUND), which may indicate deliberate obfuscation or a misconfiguration. No page title or content snapshot is available for public review, so the exact phishing landing page cannot be described.
The evidence points to a high‑risk, brand‑impersonation operation that leveraged a legitimate‑looking TLS certificate to increase credibility. Defenders should add the IP address 207.174.215.249 to network‑level deny lists, monitor DNS queries for the domain and its subdomains, and ensure that email gateways enforce strict DMARC, DKIM, and SPF checks for Google‑related communications. Continuous monitoring of the Unified Layer ASN for new malicious domains is recommended, as is sharing the indicator set with threat‑intel platforms to improve collective detection. Because the domain is currently offline, any active remediation should focus on preventing future re‑hosting of similar infrastructure.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
PD-20260621-586F23 Recipient: abuse@publicdomainregistry.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога