gl[.]nqoxur2[.]sa[.]com
“Site is created successfully!”
Сводка доказательств
gl.nqoxur2.sa.com was observed by multiple threat intelligence sources as a generic phishing infrastructure. The domain resolves to the IPv4 address 178.16.53.103, which is registered to AS202412 Omegatech LTD and geolocated to the Netherlands. Registration data shows the domain was created on 25 June 1998 through the registrar Sav.com, LLC, and is served by the four centralnic.net nameservers. No TLS certificate is present; the site is accessible only via HTTP, which further reduces trust.
The Gridinsoft trust score is 0 out of 100, indicating a lack of reputation. VirusTotal analysis recorded eight detections out of ninety‑three scanned engines, and the domain is listed on one external blocklist and has been explicitly blocked by the PhishDestroy service. The only visible page title returned by the HTTP response is “Site is created successfully!”, a generic message that provides no insight into the phishing payload or targeted brand. The current host status is reported as offline, suggesting the site has been taken down or is temporarily unavailable.
Available evidence confirms the domain’s association with phishing activity, but the exact content and victim targeting remain unknown because no page content has been captured beyond the title. Analysts should continue to monitor the IP address 178.16.53.103 for re‑hosting of malicious pages and enforce network‑level blocks for both the domain and its host. Adding the domain to internal URL filtering lists, updating intrusion detection signatures, and sharing the indicator set with upstream threat‑sharing communities are recommended mitigation steps. Given the low trust score, lack of encryption, and multiple vendor detections, the domain should be treated as high‑risk until a definitive takedown confirmation is obtained.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 13.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание