variational[.]sa[.]com
“Variational Protocol — On-Chain Derivatives Infrastructure”
Evidence Summary
Analysis of the domain variational.sa.com indicates an active high-risk crypto drainer campaign impersonating Google. The domain resolves to 188.114.96.3, an address associated with AS13335 (Cloudflare, Inc.) in the United States. Registration was facilitated through Sav.com, LLC, with nameservers under CentralNic. The SSL certificate is issued by Google Trust Services (WE1), a detail consistent with the targeted brand but not conclusive for legitimacy. The site returns an HTTP 200 status and presents the page title 'Variational Protocol — On-Chain Derivatives Infrastructure,' suggesting a focus on cryptocurrency-related fraud. Defenders should note that the domain is flagged by three security blocklists, including PhishDestroy, MetaMask, and SEAL, and has been assigned a trust score of 0/100 by Gridinsoft. Two of 91 security vendors on VirusTotal detect the domain as malicious. The infrastructure relies on Cloudflare, including Browser Insights and HTTP/3, which may complicate traditional detection methods. No evidence of takedown or registrar intervention is present as of July 12, 2026. The exact mechanics of the crypto drainer remain unconfirmed, as the page content has not been analyzed beyond the provided title. Defenders are advised to block the domain at the DNS or network level, monitor for related certificates, and investigate any connections to the IP or ASN for additional compromised assets. Further analysis of the site’s scripts or wallet addresses may clarify the drainer’s operational behavior.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 12, 2026
8 monitored external feeds No match
Detection timeline
-
Domain status
Reachable → Unreachable
Technologies
3 high-confidence technologies identified
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of variational.sa.com · checked Jul 7, 2026
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive