df[.]qeymqo2[.]sa[.]com
“Site is created successfully!”
df.qeymqo2.sa.com — Контент недоступен. Сводка доказательств: VirusTotal 11/93 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Fortinet); Google Safe Browsing flagged; PhishDestroy score 83/100. Регистратор: Sav.com.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain df.qeymqo2.sa.com is currently flagged as a generic phishing infrastructure. The domain was originally registered on June 25, 1998 through Sav.com, LLC and is served by the four centralnic.net name servers (ns1‑ns4.centralnic.net). DNS resolution points to the IPv4 address 178.16.53.103, which belongs to AS202412 owned by Omegatech LTD and is geolocated in the Netherlands. No TLS certificate is presented for the host, indicating that HTTPS is not available.
Google Safe Browsing classifies the site under social engineering, and Gridinsoft assigns a trust score of zero out of one hundred, reflecting a high likelihood of malicious intent. VirusTotal analysis shows that eleven of ninety‑three scanning engines have reported detections for the domain, confirming that multiple security vendors consider it unsafe. The site appears on one public blocklist and has been actively blocked by the PhishDestroy service. The only visible content captured is the page title “Site is created successfully!”, which does not provide any legitimate context and is typical of placeholder pages used by malicious operators.
The current operational status is offline, but the hosting infrastructure remains reachable, and the IP address continues to resolve to the domain. Defenders should therefore maintain the domain and its associated IP in block lists, monitor for any resurrection of the site, and consider implementing DNS‑level filtering for the entire centralnic.net name‑server range if broader protection is required. Continuous re‑scanning with multi‑engine services such as VirusTotal is advised to capture any future changes in the threat profile.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание