df[.]qrtnln3[.]sa[.]com
“Site is created successfully!”
証拠の概要
This domain, df.qrtnln3.sa.com, has been observed in a generic phishing campaign and is currently taken offline. The registrar record shows the domain was created on June 25, 1998 and is registered through Sav.com, LLC. Infrastructure analysis reveals that the domain resolves to the IPv4 address 178.16.53.103, which is hosted in the Netherlands and belongs to autonomous system AS202412 operated by Omegatech LTD. No TLS certificate is presented, indicating that the site served only HTTP content. The authoritative name servers are ns1.centralnic.net through ns4.centralnic.net, which are typical of CentralNic‑managed domains.
The page title returned from the live host was “Site is created successfully!”, a generic message that offers no insight into the intended victim interaction. Trust scoring from Gridinsoft assigns a zero‑point rating out of 100, reflecting a high likelihood of malicious use. VirusTotal scans report that ten out of ninety‑three antivirus and URL‑reputation engines flagged the domain, providing independent confirmation of its suspicious nature. The domain appears on a single security blocklist and is actively blocked by the PhishDestroy feed, further corroborating its classification as a phishing resource.
Because the site is offline, dynamic analysis of payloads or redirects is not possible, leaving the exact phishing technique and targeted brand unknown. Defenders should continue to block the domain at perimeter and DNS layers, monitor for any resurgence of the host, and consider adding the IP address 178.16.53.103 to reputation lists. Additional mitigation steps include reviewing outbound traffic for connections to this address, updating web‑filter rules to deny HTTP traffic to the domain, and watching for new subdomains under the same registrar that may be leveraged in future campaigns. Ongoing vigilance is advised given the low trust score, multiple vendor detections, and active blocklist listings.
Data Coverage
脅威対応 Pipeline
ブロックリストの確認範囲
監視対象の外部情報源 10 件 · 保存スナップショット 2026年8月10日
検出タイムライン
-
Cloudflare Radar
Cloudflare Radar スキャンを保存 · スキャンを開く
VirusTotalによる分析
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください