fl[.]goumah[.]cc
“goumah.cc | 520: Web server is returning an unknown error”
fl.goumah.cc — 服务器错误 (HTTP 502). 品牌冒充:Govfl; 诈骗类型:Impersonation. 证据摘要: VirusTotal 15/91 (ADMINUSLabs, BitDefender, CRDF, CyRadar, ESET); URLScan malicious verdict; PhishDestroy score 95/100. 注册商: Dominet (HK).
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain fl.goumah.cc was registered on June 12, 2026 through Dominet (HK) Limited. It currently resolves to the IPv4 address 172.67.202.182, a host that is also associated with at least one public security blocklist. The domain is classified as an active generic phishing infrastructure with an elevated risk rating. VirusTotal has recorded detections from 15 of 91 scanned security vendors, indicating that a substantial minority of AV engines flag the host as malicious. Independent block‑list services have already added the domain to their deny lists; PhishDestroy specifically lists it as blocked, confirming that the domain is being actively filtered by anti‑phishing tools.
Evidence shows that the domain’s operational timeline is short, having been created only weeks before the report date of July 29, 2026. The rapid appearance of multiple vendor detections suggests that threat actors deployed the domain in a coordinated campaign rather than as a one‑off test. The lack of publicly available SSL certificate details, HTTP response codes, or page‑title information limits the ability to assess the exact payload or credential‑harvesting technique employed. Likewise, no open‑source intelligence sources such as OTX or similar have published additional indicators of compromise for this host at the time of writing.
Defenders should prioritize adding 172.67.202.182 and the fully qualified domain name fl.goumah.cc to their DNS and endpoint block lists. Monitoring for DNS queries to the domain and for outbound connections to the associated IP can help detect compromised clients. Because the domain is already listed by PhishDestroy, integrating that feed into existing web‑gateway solutions will provide immediate protection. Ongoing threat‑intel collection is recommended to capture any future changes to the hosting environment, additional payload drops, or related command‑and‑control infrastructure that may emerge as the campaign evolves.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。