df[.]ntiqshop[.]sa[.]com
“Site is created successfully!”
Riepilogo delle prove
The domain df.ntiqshop.sa.com was created on June 25, 1998 and is currently listed as offline. Registration records show the domain was acquired through Sav.com, LLC, and it is served by the four CentralNic nameservers ns1.centralnic.net through ns4.centralnic.net. DNS resolution points to the IP address 178.16.53.103, which belongs to AS202412 Omegatech LTD and is geolocated in the Netherlands. No TLS certificate is present for the host, indicating that communications are unencrypted.
The site’s HTTP response included the page title "Site is created successfully!"; no additional content has been captured, and the exact nature of the landing page remains unverified. Threat intelligence sources have recorded the domain on a single security blocklist and it is actively blocked by the PhishDestroy feed. VirusTotal analysis shows that 13 of 93 scanning engines flagged the domain, reflecting a moderate detection consensus. Independent scoring from Gridinsoft assigns a trust rating of 0 out of 100, underscoring the high confidence that the domain is malicious.
The combination of blocklist presence, multiple vendor detections, a zero trust score, and the lack of SSL collectively indicate that df.ntiqshop.sa.com is being used for a generic phishing campaign. Defensive teams should ensure that the IP 178.16.53.103 and the associated domain are added to network deny lists, monitor for any residual DNS queries, and verify that any client‑side controls (such as web filtering and endpoint protection) are updated to block the domain. Continuous observation of the hosting ASN and associated WHOIS changes is advised to detect potential re‑activation or repurposing of the infrastructure.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 11/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo