fl[.]goumad[.]cc
“goumad.cc | 520: Web server is returning an unknown error”
证据摘要
fl.goumad.cc was registered through NameSilo, LLC on 12 June 2026 and began resolving to the address 104.21.71.34 shortly thereafter. The hosting IP belongs to a Cloudflare network used by multiple unrelated sites, which complicates attribution but does not mitigate the observed malicious activity. The domain appears on a single security blocklist and has been actively blocked by the PhishDestroy feed, indicating that at least one operational phishing detector has identified traffic associated with the domain. VirusTotal reports that 11 of 91 scanning engines have flagged the domain as malicious, a ratio that exceeds typical background noise for newly created domains and aligns with the elevated risk rating assigned by the database.
The current risk level is listed as elevated and the domain status is active, suggesting that malicious infrastructure is still reachable. The available evidence does not include a page title, SSL certificate details, HTTP response codes, or any brand‑specific lures, so the precise phishing vector cannot be confirmed at this time. Analysts should therefore treat the domain as a generic phishing platform and assume that any URLs hosted on the same IP may be used to deliver credential‑stealing pages, malicious downloads, or redirect victims to further compromised infrastructure. Defenders are advised to add 104.21.71.34 to inbound and outbound network deny lists, enforce URL filtering for the fully qualified domain name fl.goumad.cc, and monitor DNS query logs for recent resolution attempts.
Because the registrar is NameSilo, LLC, it is worthwhile to flag the registrar in any automated takedown workflow. Continued scanning with sandbox environments and periodic re‑query of VirusTotal are recommended to capture any changes in the detection score. Logging of any user‑initiated connections to the domain should be correlated with authentication failures to identify potential compromise attempts.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月13日
检测时间线
-
VirusTotal
10 → 12
-
域名状态
可访问 → 无法访问
域名情报
技术详情DNS、TLS 名称和时间戳
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控