df[.]nulqmj3[.]za[.]com
“Site is created successfully!”
Сводка доказательств
The domain df.nulqmj3.za.com is currently listed as offline but retains a set of indicators that warrant continued monitoring. Registration data shows the domain was created on March 24, 1998 through Sav.com, LLC, and it is served by the four centralnic.net nameservers (ns1.centralnic.net, ns2.centralnic.net, ns3.centralnic.net, ns4.centralnic.net). DNS resolution points to the IPv4 address 178.16.53.103, which belongs to AS202412 owned by Omegatech LTD and is geolocated in the Netherlands. No SSL/TLS certificate is presented for the host, indicating that any web traffic would occur over clear‑text HTTP.
The only visible page title retrieved before the domain was taken offline reads “Site is created successfully!”. Gridinsoft assigns a trust score of 0 out of 100, reflecting a lack of confidence in the site’s legitimacy. VirusTotal analysis shows that six of ninety‑three scanning engines flagged the domain as malicious, and the domain appears on a single external blocklist. It has also been actively blocked by the PhishDestroy service, reinforcing the assessment of a phishing‑related threat.
The threat classification is generic phishing and the risk level is elevated. While the exact phishing campaign details (e.g., targeted brand or credential‑capture mechanisms) are not disclosed, the combination of a zero trust score, multiple vendor detections, blocklist presence, and the lack of encryption suggests a high probability of credential‑stealing or credential‑relay activity. Defenders should ensure that the IP address 178.16.53.103 is denied at network perimeters, update URL filtering rules to include df.nulqmj3.za.com, and maintain watchlists for any re‑activation of the domain. Continuous re‑scanning of the host after any status change is advised to capture potential alterations in payload or hosting infrastructure.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 13.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание