jhdqsl.com
“ERROR 404 - Not Found!”
Evidence Summary
This domain, jhdqsl.com, has been identified as a credential theft phishing site targeting user login credentials. Analysis indicates the domain is currently offline, though prior activity suggests malicious intent to harvest sensitive authentication data. No specific brand impersonation was confirmed, but the domain exhibits characteristics consistent with credential harvesting operations. Infrastructure analysis reveals the domain was flagged by 18 of 95 security vendors on VirusTotal, indicating moderate detection coverage. Registered through Gname.com Pte. Ltd. on May 14, 2020, the domain resolves to the IP address 172.67.149.229, hosted on AS13335 (Cloudflare, Inc.). The SSL certificate is issued by Let's Encrypt (R13), a common choice for both legitimate and malicious domains. The domain appears on two security blocklists, specifically PhishDestroy and PhishingDB, further corroborating its malicious classification. The page title, ERROR 404 - Not Found, suggests either a takedown or temporary deactivation of the phishing content. Current status confirms the domain is offline, reducing immediate risk to end users. However, historical activity and infrastructure indicators warrant continued monitoring. Organizations are advised to block the domain and associated IP (172.67.149.229) at the perimeter firewall and DNS filtering levels. Security teams should review logs for prior connections to this domain or IP, particularly from endpoints exhibiting anomalous authentication attempts. Users should be reminded to verify domain authenticity before entering credentials, especially on sites lacking valid SSL certificates or exhibiting unusual URL structures. Given the domain's age and hosting provider, further investigation into related infrastructure is recommended to identify potential linked threats.
Network Security Intelligence
Forensic History & Detection Timeline
-
Cloudflare Radar Scan Mar 7, 2026 · 15:22 UTCCloudflare Radar scan registered: View Radar report.
-
Domain Status Transition Mar 1, 2026 · 06:45 UTCDomain state transitioned from alive to dead.
Threat Response Pipeline
Public Blocklist Status
Technologies · 3 identified
VirusTotal Analysis
Archived Evidence
Community reports
Reported by 1 community member, first seen Nov 3, 2025
- Stored reports
- 1
- Unique reported URLs
- 1
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive