gumlree[.]form1189[.]cfd
gumlree.form1189.cfd — 内容不可用. 证据摘要: VirusTotal 14/93 (BitDefender, Certego, CRDF, CyRadar, ESET); PhishDestroy score 92/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain gumlree.form1189.cfd was registered on February 21, 2026 and presently resolves to the IPv4 address 104.21.94.33. That address is owned by Cloudflare, Inc. (AS13335) and is geolocated to the United States. The site is currently taken offline, and the HTTP response returns a generic page with the title “Just a moment…”. The SSL certificate presented for the host is identified as WE1, but no further validation details are available.
Reputation checks show a Gridinsoft trust score of 0 out of 100, indicating a complete lack of trust. VirusTotal has recorded 14 positive detections out of 93 scanned security vendors, confirming that multiple anti‑malware engines recognize the domain as malicious. The domain appears on one external security blocklist and is specifically listed by PhishDestroy as a phishing source. No additional context such as targeted brand, specific phishing kit, or observed payloads is disclosed in the current dataset.
The combination of a newly‑created domain, Cloudflare‑served IP, low trust score, multiple vendor detections, and inclusion on a dedicated phishing blocklist suggests a high confidence that this domain is being used for a phishing campaign. Defenders should immediately block DNS resolution and HTTP(S) requests to gumlree.form1189.cfd at the network perimeter, update endpoint and web‑gateway filtering rules, and monitor for any residual connections to the associated Cloudflare IP. Because the site is offline, ongoing investigation may be limited; however, threat‑intel feeds should be queried for any related indicators of compromise, and any observed malicious emails or login attempts that reference the domain should be quarantined and analyzed.
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
SHORTDOT 域名区 · 公开证据
.cfd
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。