egdqpb[.]sbs
“TikTok”
ملخص الأدلة
Analysis of the domain egdqpb.sbs shows a deliberate brand‑impersonation campaign aimed at TikTok users. The site was registered through Dynadot LLC on August 10, 2025 and resolves to the IPv4 address 38.46.13.34, which is associated with AS9294 GNET INC. in Hong Kong. No SSL certificate is present, indicating that the site operated over plain HTTP before being taken offline. The page title returned by the server is "TikTok," matching the declared brand target and reinforcing the impersonation intent. Infrastructure observations reveal the domain uses the generic nameservers ns1.dnsip.com and ns2.dnsip.com, a pattern commonly seen in fast‑flux or low‑cost hosting setups.
Threat‑intelligence feeds have flagged the domain in two AlienVault OTX pulses, and PhishDestroy has listed it as blocked. VirusTotal records indicate that 17 of 93 scanning engines flagged the domain, reflecting a moderate level of detection across commercial security products. Gridinsoft assigns a trust score of 0 out of 100, and the domain appears on one additional security blocklist, further confirming its malicious reputation.
Current status is offline, limiting immediate exposure, but the infrastructure details remain relevant for defenders. The lack of an SSL certificate, the use of generic DNS services, and the Hong Kong hosting location suggest a low‑cost, opportunistic operation rather than a sophisticated actor. Uncertainty remains regarding the specific payload or credential‑harvesting mechanisms, as no page content analysis is available.
Defenders should continue to block egdqpb.sbs at network perimeters and update endpoint protection signatures to reflect the observed VirusTotal detections. Monitoring for new domains registered through Dynadot with similar naming patterns or using the same nameservers can aid early detection. Additionally, threat‑intel teams should correlate future sightings with the two OTX pulses to track potential campaign evolution.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026
المخطط الزمني للاكتشاف
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
نطاق SHORTDOT · أدلة عامة
.sbs
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب