Phishing detection: googleplaydown.com
Google Investigate
Domain
googleplaydown.com0 CT hosts on apex
IP
172.67.162.6
URL
http://googleplaydown.com
Cert
WE1
Phishunt analysis Beta
27
low suspicionheuristic risk score · not a probability
Why?
- +5.3 Keyword match
- +5.1 Site cluster
- +3.7 Brand in domain label
- +3.2 Young domain
- +3.0 TweetFeed
- +2.2 ASN reputation
- +1.1 No CSP header
- +1.1 No HSTS header
- +0.9 No registrar lock
- +0.7 Brand in cert SAN
- +0.5 Young certificate
- +0.4 Long domain
- +0.3 Free CA
- +0.2 Suspicious TLD
16 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting
Site impersonates Google Play by embedding the brand in its domain name, likely luring victims into fraudulent app downloads or harvesting Google account credentials. Flagged as malicious by TweetFeed threat intelligence; hosted behind Cloudflare with minimal RDAP registration data.
Brand in domain labelTweetFeedKeyword match
AI-generated from stored detector signals - the AI never visited the site. · 2026-07-23 · confidence 65%
Domain & Network
Whois
Registrar
Porkbun LLC
Network
IP
172.67.162.6
Country
United States
Hosting
Cloudflare, Inc.
ASN
AS13335
TLS Cert
WE1
External detection
TweetFeed
CleanGoogle Safe Browsing · OpenPhish · PhishTank · urlscan.io
Requests
Resources
Observables
Related websites
Report this phishing
Submit to blocklists
urlscan
VirusTotal
Whois
ipinfo
Greynoise