gl[.]qxzqqp6[.]sa[.]com
“Site is created successfully!”
gl.qxzqqp6.sa.com — Contenido no disponible. Resumen de las pruebas: VirusTotal 13/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); Google Safe Browsing flagged; PhishDestroy score 89/100. Registrador: Sav.com.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of gl.qxzqqp6.sa.com indicates a high‑risk generic phishing infrastructure that is currently taken offline. The domain resolves to the IPv4 address 178.16.53.103, which is assigned to AS202412 operated by Omegatech LTD in the Netherlands. No TLS certificate is presented for the host, meaning all HTTP traffic would be unencrypted. The site title returned during the brief scan reads "Site is created successfully!", offering no substantive content and suggesting a placeholder or abandoned landing page. Google Safe Browsing classifies the domain under social engineering, and the platform’s detection engines flagged it as malicious, confirming the phishing nature.
VirusTotal records show that 13 of 93 security vendors have flagged the domain, providing additional corroboration of malicious intent. The registrar listed is Sav.com, LLC, and the domain was originally registered on 25 June 1998, an unusually long lifespan for a phishing site, which may indicate reuse of legacy infrastructure. Gridinsoft assigns a trust score of 0 out of 100, and the domain appears on a single public blocklist, further reinforcing its unsafe status. PhishDestroy has explicitly blocked the domain, indicating that known anti‑phishing feeds already recognize it as a threat.
Nameservers are hosted on the centralnic.net network (ns1‑ns4.centralnic.net). Defenders should continue to block the IP address 178.16.53.103 and the domain gl.qxzqqp6.sa.com at perimeter and DNS layers, monitor for any re‑activation, and ensure that any outbound traffic to this host is logged and investigated. Given the lack of SSL and the placeholder page title, there is limited evidence of active credential‑harvesting pages, but the combination of multiple vendor detections, Safe Browsing flags, and low trust score warrants immediate preventive action. Continuous monitoring of associated IP ranges and the registrar’s new registrations is recommended to detect possible resurgence of malicious activity.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.