hf[.]onewaybanner[.]sa[.]com
“Site is created successfully!”
Résumé des preuves
Analysis as of July 24, 2026 indicates that the domain hf.onewaybanner.sa.com is currently offline but was previously resolved to the IPv4 address 178.16.53.103 located in the Netherlands and assigned to AS202412 (Omegatech LTD). The authoritative name servers are ns1.centralnic.net through ns4.centralnic.net, and the domain was registered through Sav.com, LLC on June 25, 1998. No TLS certificate was observed, meaning the site operated without HTTPS. The only publicly visible page title retrieved before takedown was “Site is created successfully!”, which does not reveal a target brand or specific service. Google Safe Browsing classifies the URL as a social engineering threat, and the domain appears on the PhishDestroy blocklist.
VirusTotal reports that 13 of 93 scanners flagged the domain, indicating a moderate level of detection across anti‑malware engines. Gridinsoft assigns a trust score of 0 out of 100, reinforcing the malicious assessment. The domain is listed on one additional security blocklist, further confirming its abuse. While the exact phishing campaign or impersonated brand cannot be identified from the available data, the combination of social‑engineering labeling, multiple vendor detections, and a zero trust score suggest that the site was used to lure victims into disclosing credentials or personal information.
Defenders should add hf.onewaybanner.sa.com to URL filtering, DNS sinkhole, and endpoint blocklists, monitor for any future resolution to new IPs, and consider scanning internal logs for prior connections to the IPv4 address 178.16.53.103. Because the domain lacks HTTPS, any traffic to it would have been unencrypted, simplifying credential capture. Continuous threat‑intel feeds should be consulted for updates, and incident response teams should treat any observed traffic as potentially compromised.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 12/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif