africangulf[.]ly
“Index of /”
证据摘要
This domain, africangulf.ly, poses a high-risk brand impersonation threat targeting Google users. The site is designed to mimic legitimate Google services, tricking visitors into entering sensitive credentials such as usernames, passwords, or other authentication details. Once submitted, these credentials are harvested by threat actors for unauthorized account access, financial fraud, or further phishing campaigns. The risk is amplified by the domain's professional appearance, which increases the likelihood of successful deception, particularly among users who may not scrutinize URLs or SSL certificates closely. Analysis indicates this domain was registered on September 21, 2021, through LTT local, a registrar associated with high-risk infrastructure. The domain resolves to IP address 62.240.36.36, hosted on AS21003 (General Post and Telecommunication Company) in Libya, a region frequently linked to malicious activity. Security vendors have flagged africangulf.ly as malicious, with 19 out of 95 engines on VirusTotal detecting it as phishing. The site appears on two security blocklists, including PhishDestroy and PhishingDB, and is explicitly labeled as phishing by Google Safe Browsing. The SSL certificate, issued by Let's Encrypt (R13), provides a false sense of security, as it does not validate the legitimacy of the site's content or ownership. If you visited africangulf.ly or entered any credentials, immediate action is required to mitigate potential damage. First, change the passwords for any accounts accessed or entered on the site, prioritizing email, financial, and work-related services. Enable multi-factor authentication (MFA) on all critical accounts to prevent unauthorized access, even if credentials were compromised. Monitor accounts for suspicious activity, such as unrecognized logins, password reset emails, or unauthorized transactions. If financial information was submitted, contact your bank or payment provider to report potential fraud and request a review of recent transactions. Additionally, scan your device for malware using updated security tools, as phishing sites may deploy malicious scripts or redirect to exploit kits. Finally, report the domain to your organization's security team or relevant authorities to aid in takedown efforts and protect other potential victims.
Data Coverage
安全信号
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of africangulf.ly · checked Mar 1, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控