m9[.]dzcidz5[.]sa[.]com
“Site is created successfully!”
m9.dzcidz5.sa.com — Conteúdo indisponível. Resumo das evidências: VirusTotal 6/93 (CyRadar, Fortinet, Gridinsoft, MalwareURL, Trustwave); PhishDestroy score 68/100. Registrador: Sav.com.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
On 25 July 2026 a technical review of the domain m9.dzcidz5.sa.com was completed. The domain is listed as offline and does not present an active HTTPS endpoint; no SSL certificate was observed. Registration data shows the domain was created on 25 June 1998 and was registered through Sav.com, LLC. The authoritative name servers are ns1.centralnic.net, ns2.centralnic.net, ns3.centralnic.net, and ns4.centralnic.net, indicating use of the CentralNic registry infrastructure. DNS resolution points to the IPv4 address 178.16.53.103, which belongs to AS202412 owned by Omegatech LTD and is geolocated in the Netherlands.
The page title returned during the brief availability window was "Site is created successfully!", providing no direct indication of malicious intent beyond the generic nature of the message. Reputation scoring from Gridinsoft assigned a trust score of 0 out of 100, the lowest possible rating. VirusTotal analysis recorded six detections out of ninety‑three scanned security vendors, confirming that multiple AV engines flagged the domain as malicious. The domain is currently blocked by the PhishDestroy service and appears on one public security blocklist, further corroborating its classification as a threat.
Although the precise phishing payload or target brand was not captured, the combination of low trust score, multi‑vendor detections, and blocklist presence suggests the domain was used for generic phishing campaigns. Defenders should continue to block any resolution of 178.16.53.103 and add m9.dzcidz5.sa.com to internal deny lists. Monitoring of the registrar Sav.com, LLC and the CentralNic name‑server set may reveal future re‑activations. Given the offline status, periodic re‑scans are advisable to detect any potential re‑deployment of malicious content.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo