MALICIOUS — CRITICAL
h2[.]sdvu[.]click
15 of 93 security engines flagged the domain.
- VirusTotal
- 15/93
- Blocklists
- No stored match
- التوفر
- لم يتم التحقق منها
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
h2.sdvu.click — لم يتم التحقق منها. نوع الاحتيال: Impersonation. ملخص الأدلة: VirusTotal 15/93 (ADMINUSLabs, BitDefender, CRDF, CyRadar, ESET); Spamhaus DBL_SPAM; PhishDestroy score 95/100. مسجّل النطاق: Sav.com.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Digest
h2.sdvu.click is classified critical with an evidence score of 95/100. 15 of 93 security engines flagged the domain. Registered 30 Aug 2025 via Sav.com, LLC, hosted on 178.16.53.103 (RAILNET Railnet LLC, US, NL).
Stored generated summary (templated)mistral · 23/07/2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
This domain, h2.sdvu.click, was registered on August 30, 2025, through Sav.com, LLC, and is associated with phishing activity targeting unspecified brands or services. Infrastructure analysis reveals Cloudflare nameservers (augustus.ns.cloudflare.com, laura.ns.cloudflare.com) and resolution to a Netherlands-based IP, 178.16.53.103, hosted on AS202412 (Omegatech LTD). The domain lacks an SSL certificate, increasing the likelihood of unencrypted credential harvesting or malware distribution. At the time of assessment, the domain displayed a default placeholder page with the title 'Site is created successfully!', indicating either a recently deployed or abandoned phishing infrastructure.
Detection data from July 2026 shows 15 of 93 security vendors on VirusTotal flagged the domain as malicious, while PhishDestroy and at least one other security blocklist have actively blocked it. The domain was taken offline prior to analysis, limiting further forensic examination of its intended payload or target. Gridinsoft assigned a trust score of 0/100, reinforcing its classification as high-risk.
Defenders should treat this domain as part of a broader phishing campaign, particularly given its use of Cloudflare for potential anonymization and the absence of legitimate content. Network-level blocking is recommended for any residual resolution attempts, and retrospective log analysis should be conducted to identify prior interactions with this domain. No specific phishing kit or targeted brand was identified in the available data.
نطاق تغطية البيانات12 recorded checks
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
Registration: sdvu.click
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain sdvu.click behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
الأدلة المؤرشفة
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of h2.sdvu.click · checked Mar 2, 2026
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.