Phishing detection: wegoupupup.com

Google
https://wegoupupup.com/v3/signin/identifier?continue=https://accounts.google.com/o/oauth2/programmatic_auth?lang%3Den%26cc%3DUS%26langCountry%3Den_US%26xoauth_display_name%3DPixel%2B8%26tmpl%3Dnew_account%26source%3Dandroid%26return_user_id%3Dtrue%26client_id%3D1070009224336-sdh77n7uot3oc99ais00jmuft6sk2fg9.apps.googleusercontent.com%26scope%3Dhttps://www.google.com/accounts/OAuthLogin%26access_type%3Doffline%26set_oauth_token_cookie%3Dtrue%26hl%3Den_US&faa=1&followup=https://accounts.google.com/o/oauth2/programmatic_auth?lang%3Den%26cc%3DUS%26langCountry%3Den_US%26xoauth_display_name%3DPixel%2B8%26tmpl%3Dnew_account%26source%3Dandroid%26return_user_id%3Dtrue%26client_id%3D1070009224336-sdh77n7uot3oc99ais00jmuft6sk2fg9.apps.googleusercontent.com%26scope%3Dhttps://www.google.com/accounts/OAuthLogin%26access_type%3Doffline%26set_oauth_token_cookie%3Dtrue%26hl%3Den_US&hl=en_US&passive=1209600&rart=ANgoxcfJ4FDmoJk_0mVSJ3wAvGY-tlGIWGvQW-gdUcoK_CV6lgMr45_kQjoge1I1Dj4-H6jeQ9WIw9-8V0Twn-I5ukPIFQqM6xGJYRNHgPtWQTJbog-zGfo&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-1408957660:1788682985013131 Access site
Screenshot
Screenshot of wegoupupup.com
Investigate
URL https://wegoupupup.com/v3/signin/identifier?continue=https:…
Phishunt analysis Beta
45 high suspicion likely_phishingheuristic risk score · not a probability
Why?
  • +6.1 Google Safe Browsing
  • +5.3 Keyword match
  • +5.1 Site cluster
  • +4.1 Brand in screenshot
  • +4.0 Young domain
  • +3.2 Brand favicon
  • +3.0 OpenPhish
  • +2.1 ASN reputation
  • +1.6 Favicon (kit)
  • +1.1 No CSP header
  • +0.9 Young certificate
  • +0.6 Brand impersonation in path
  • +0.6 Login text in screenshot
  • +0.6 Registrar reputation
  • +0.4 Credential path
  • +0.3 Free CA
  • +0.3 Long domain
  • +0.2 Obfuscated JavaScript
  • +0.2 Suspicious TLD
  • Boosted to 45: Google-flagged credential form
23 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting

Google account phishing site spoofing the OAuth sign-in flow by embedding the brand in the URL path on an unrelated domain. Flagged by Google Safe Browsing and confirmed by OpenPhish. Uses obfuscated JavaScript and Cloudflare hosting to evade detection.

Google Safe BrowsingOpenPhishCredential path
AI-generated from stored detector signals - the AI never visited the site. · 2026-09-06 · confidence 85%
Domain & Network
Whois
Network
Country United StatesUnited States
ASN AS13335
TLS Cert WE1
External detection Google Safe Browsing OpenPhish
GSB category: SOCIAL_ENGINEERING
CleanPhishTank · TweetFeed · urlscan.io · SANS ISC
Report this phishing
Network / ASN Cloudflare, Inc.

Tracked from 2026-09-06 13:04 UTC  ·  Last refreshed 2026-09-07 15:30 UTC