On 30 July 2026 analysts observed that the domain saq31.cn continues to host a generic phishing infrastructure. The domain was registered on 10 January 2026 through 北京新网数码信息技术有限公司 and is served by the authoritative name servers dm1.longmingdns.com and dm2.longmingdns.com. DNS resolution points to the IPv4 address 154.26.231.27, which remains reachable and is listed as active at the time of writing. The domain appears on three independent security blocklists and has been explicitly blocked by the PhishDestroy, MetaMask, and SEAL filtering platforms, indicating that multiple downstream defenses have already identified it as malicious.
A VirusTotal scan submitted the domain to 91 antivirus and URL‑reputation engines; at the time of the scan no engine raised a detection, which does not constitute evidence of benign behavior and should be interpreted as a lack of current signatures rather than clearance. No public information is available regarding SSL certificate details, HTTP response codes, Safe Browsing status, Open Threat Exchange entries, or page title, leaving the exact content and target brand of the phishing lure unverified. Consequently, defenders cannot rely on content‑based indicators and must focus on network‑level controls. Recommended mitigations include adding saq31.cn and its resolving IP 154.26.231.27 to firewall deny lists, updating DNS sinkhole policies, and ensuring that email security gateways reference the latest blocklist feeds that already flag the domain.
Continuous monitoring of the IP address for any changes in hosting or additional malicious payloads is advised, as well as periodic re‑scanning with VirusTotal or similar services to capture emerging signatures. Organizations should also audit internal logs for any outbound connections to the domain or IP, and quarantine any user‑initiated sessions that attempt to resolve or contact the site.