hf[.]onewaybanner[.]sa[.]com
“Site is created successfully!”
Riepilogo delle prove
Analysis as of July 24, 2026 indicates that the domain hf.onewaybanner.sa.com is currently offline but was previously resolved to the IPv4 address 178.16.53.103 located in the Netherlands and assigned to AS202412 (Omegatech LTD). The authoritative name servers are ns1.centralnic.net through ns4.centralnic.net, and the domain was registered through Sav.com, LLC on June 25, 1998. No TLS certificate was observed, meaning the site operated without HTTPS. The only publicly visible page title retrieved before takedown was “Site is created successfully!”, which does not reveal a target brand or specific service. Google Safe Browsing classifies the URL as a social engineering threat, and the domain appears on the PhishDestroy blocklist.
VirusTotal reports that 13 of 93 scanners flagged the domain, indicating a moderate level of detection across anti‑malware engines. Gridinsoft assigns a trust score of 0 out of 100, reinforcing the malicious assessment. The domain is listed on one additional security blocklist, further confirming its abuse. While the exact phishing campaign or impersonated brand cannot be identified from the available data, the combination of social‑engineering labeling, multiple vendor detections, and a zero trust score suggest that the site was used to lure victims into disclosing credentials or personal information.
Defenders should add hf.onewaybanner.sa.com to URL filtering, DNS sinkhole, and endpoint blocklists, monitor for any future resolution to new IPs, and consider scanning internal logs for prior connections to the IPv4 address 178.16.53.103. Because the domain lacks HTTPS, any traffic to it would have been unencrypted, simplifying credential capture. Continuous threat‑intel feeds should be consulted for updates, and incident response teams should treat any observed traffic as potentially compromised.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 11/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo