Phishing detection: googleplaydown.com

Google
http://googleplaydown.com Access site
Screenshot
Screenshot of googleplaydown.com
Phishunt analysis Beta
27 low suspicionheuristic risk score · not a probability
Why?
  • +5.3 Keyword match
  • +5.1 Site cluster
  • +3.7 Brand in domain label
  • +3.2 Young domain
  • +3.0 TweetFeed
  • +2.2 ASN reputation
  • +1.1 No CSP header
  • +1.1 No HSTS header
  • +0.9 No registrar lock
  • +0.7 Brand in cert SAN
  • +0.5 Young certificate
  • +0.4 Long domain
  • +0.3 Free CA
  • +0.2 Suspicious TLD
16 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting

Site impersonates Google Play by embedding the brand in its domain name, likely luring victims into fraudulent app downloads or harvesting Google account credentials. Flagged as malicious by TweetFeed threat intelligence; hosted behind Cloudflare with minimal RDAP registration data.

Brand in domain labelTweetFeedKeyword match
AI-generated from stored detector signals - the AI never visited the site. · 2026-07-23 · confidence 65%
Domain & Network
Whois
Registrar Porkbun LLC
Network
Country United StatesUnited States
ASN AS13335
TLS Cert WE1
External detection TweetFeed
CleanGoogle Safe Browsing · OpenPhish · PhishTank · urlscan.io
Report this phishing
Network / ASN Cloudflare, Inc.

Tracked from 2026-06-23 02:00 UTC  ·  Last refreshed 2026-08-23 07:30 UTC