MALICIOUS — HIGH
app-varitionals[.]sa[.]com
app-varitionals.sa.com is currently listed as an active generic phishing infrastructure.
- VirusTotal
- 2/91
- Blocklists
- 2 · MetaMask, SEAL
- 가용성
- 콘텐츠를 사용할 수 없음 · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
app-varitionals.sa.com — 콘텐츠를 사용할 수 없음 (HTTP 502). 증거 요약: VirusTotal 2/91 (ChainPatrol, LevelBlue); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. 등록기관: Sav.com.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
Evidence Analysis
app-varitionals.sa.com is currently listed as an active generic phishing infrastructure. The domain resolves to 104.21.93.113 and is served through Cloudflare nameservers camilo.ns.cloudflare.com and sarah.ns.cloudflare.com, indicating use of a CDN for concealment. PhishDestroy has already blocked the domain and it appears on at least one external security blocklist. VirusTotal analysis shows that 2 of 95 scanning engines have flagged the domain, reinforcing the suspicion of malicious intent. No additional public intelligence such as Safe Browsing entries, OTX mentions, or SSL certificate details are available at this time. At present, no page title or brand targeting information has been published, so the specific lure employed by the site cannot be identified. The lack of publicly visible SSL certificate details also limits verification of potential spoofed domains. The limited detection footprint suggests that the site may be newly deployed or employing techniques to avoid widespread indexing. Because the domain is still active, defenders should proactively deny outbound connections to the resolved IP address and add the domain to local DNS blocklists. Monitoring of DNS queries for the domain and its associated nameservers can provide early warning of internal attempts to reach the site. Network traffic inspection should include detection of HTTP or HTTPS requests to the IP 104.21.93.113, and any credential submission to this host should be treated as compromised. Incident response teams should consider the domain as a high‑risk indicator and correlate any related phishing emails with the observed infrastructure. Continued observation of VirusTotal and other reputation services is recommended to capture any additional detections that may emerge as the campaign evolves.
데이터 적용 범위13 recorded checks
위협 대응 Pipeline
공개 차단 목록 상태
위협 인텔리전스 교차 확인 · source references
사용 기술 · 3 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 신뢰도 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 신뢰도 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 신뢰도 100%VirusTotal 분석
보관된 증거
사이트 성능 분석
Google PageSpeed Insights — mobile performance audit of app-varitionals.sa.com · checked Jul 21, 2026
증거 및 외부 보고서Independent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.