hf[.]owvolf1[.]sa[.]com
“Site is created successfully!”
hf.owvolf1.sa.com — Conteúdo indisponível. Resumo das evidências: VirusTotal 13/93 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET); Google Safe Browsing flagged; PhishDestroy score 89/100. Registrador: Sav.com.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, hf.owvolf1.sa.com, is currently listed as offline but retains a high‑risk classification for generic phishing. The authoritative DNS records point to four CentralNIC nameservers (ns1.centralnic.net through ns4.centralnic.net) and resolve to the IPv4 address 178.16.53.103, which is advertised as belonging to AS202412 Omegatech LTD in the Netherlands. No TLS certificate is presented for the host, indicating that any HTTP service would be delivered over cleartext. The only observable HTTP artifact is the page title “Site is created successfully!”, which does not reveal a targeted brand or credential‑capture page and suggests a generic landing page.
Google Safe Browsing has flagged the domain for social engineering, and VirusTotal reports that 13 of 93 scanned security vendors classify the host as malicious, reinforcing the phishing assessment. The Gridinsoft trust score is 0 / 100, and the domain appears on a single external blocklist, having been explicitly blocked by the PhishDestroy service. Registration data show the domain was created on 25 June 1998 through Sav.com, LLC, a long‑standing registrar.
While the offline status limits immediate traffic observation, the combination of a low trust score, multiple vendor detections, and blocklist inclusion indicates an active malicious infrastructure. Defenders should continue to deny any connections to the IP 178.16.53.103, add the domain to internal blocklists, and monitor for any re‑hosting attempts. Additional analysis of the HTTP response body, if the site resurfaces, would be required to confirm the phishing payload and to identify any credential‑stealing forms or redirects.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo