sandadata[.]com[.]ng
Verificação de phishing e segurança de sandadata.com.ng
“Dankurmi Data | A technology platform that offers solutions to digital needs ...”
sandadata.com.ng — Erro no servidor (HTTP 502). Representação da marca: Google; Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 3/91 (alphaMountain.ai, CRDF, Gridinsoft); PhishDestroy score 65/100. Registrador: HostAfrica.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis indicates that sandadata.com.ng was registered on August 11, 2025 through HostAfrica and uses the nameservers dns1.webproserver.com and dns2.webproserver.com. The domain resolves to the IPv4 address 192.3.190.188, which is hosted by AS36352 (HostPapa) in the United States. No TLS certificate is presented, meaning the site is served over plain HTTP. The page title returned from the live host – “Dankurmi Data | A technology platform that offers solutions to digital needs at best possible price without compromising quality.
data, airtime, electricity, cable, airtime to cash, all available for” – does not reference the targeted brand, but the intelligence file classifies the activity as credential phishing that impersonates Google. VirusTotal records show that one of ninety‑five scanning engines flagged the domain, and the site appears on a single security blocklist. PhishDestroy has already taken the domain offline, and the Gridinsoft trust score is 0 out of 100, indicating a lack of reputation. The combination of a newly created domain, lack of encryption, low trust score, and a single vendor detection suggests a low‑volume, targeted impersonation campaign rather than a large‑scale operation.
Uncertainty remains around the actual phishing payload, the presence of any login form, and whether additional infrastructure such as command‑and‑control servers is associated with the IP address. Defenders should block the domain at perimeter filters, add the IP address 192.3.190.188 to deny‑list rules, and monitor for any DNS queries to the listed nameservers. Because the domain is already offline, ongoing threat hunting should focus on any recent credential submissions that reference Google credentials and on correlating user reports with the timeframe of the domain’s activity. Continuous review of host‑based detections for the AS36352 network may reveal further related campaigns.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo