web-google1[.]com[.]cn
Перевірка домену web-google1.com.cn на фішинг і безпеку
“谷歌浏览器-快速安全的网络浏览器,专为您而打造”
web-google1.com.cn — Контент недоступний (HTTP 502). Уособлення бренду: Google; Тип шахрайства: Tech Support Scam. Зведення доказів: VirusTotal 10/91 (alphaMountain.ai, BitDefender, CyRadar, ESET, Fortinet); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 80/100. Реєстратор: Web Commerce Communica….
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of the domain web-google1.com.cn shows a high‑risk, brand‑impersonation infrastructure that was taken offline prior to the report date of July 23, 2026. The domain was registered on February 21, 2026 through Web Commerce Communications Limited and resolves to the IP address 156.244.176.137, which is hosted in Hong Kong and announced by ASN 9294 GNET INC. No SSL certificate is presented for the site, indicating that communications are unencrypted. The web page returns the title "谷歌浏览器-快速安全的网络浏览器,专为您而打造," directly referencing Google and confirming the intent to masquerade as the Google browser product. The site is classified as a tech‑support scam, a common vector for credential theft and monetary extortion.
Detection evidence shows that 12 of 93 security vendors on VirusTotal flagged the domain as malicious, and the domain appears on three independent security blocklists, including PhishDestroy, MetaMask, and SEAL. These blocklists have already taken action to prevent resolution for end‑users. The nameservers a10.share-dns.com and b10.share-dns.net are typical of fast‑flux or shared DNS services, which can aid rapid redeployment of the infrastructure if the operator chooses to reactivate the site. Uncertainties remain regarding the specific payload or phishing pages that were served, as the site is currently offline and no additional content analysis is available.
No evidence of a valid TLS certificate, redirect chains, or additional sub‑domains was observed. Defenders should update perimeter filters to block the listed nameservers and the resolved IP address, add web-google1.com.cn to domain reputation and URL filtering lists, and monitor for any re‑registration attempts that reuse the same registrar or hosting ASN. Continuous telemetry from endpoint detection platforms should watch for the 12 vendor signatures that previously flagged the domain, as they may indicate related malicious binaries or scripts.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | web-google1.com.cn |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
PD-20260210-3A92A5 Recipient: a312636180@gmail.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога