gl[.]qxzqqp6[.]sa[.]com
“Site is created successfully!”
gl.qxzqqp6.sa.com — Контент недоступен. Сводка доказательств: VirusTotal 13/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); Google Safe Browsing flagged; PhishDestroy score 89/100. Регистратор: Sav.com.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of gl.qxzqqp6.sa.com indicates a high‑risk generic phishing infrastructure that is currently taken offline. The domain resolves to the IPv4 address 178.16.53.103, which is assigned to AS202412 operated by Omegatech LTD in the Netherlands. No TLS certificate is presented for the host, meaning all HTTP traffic would be unencrypted. The site title returned during the brief scan reads "Site is created successfully!", offering no substantive content and suggesting a placeholder or abandoned landing page. Google Safe Browsing classifies the domain under social engineering, and the platform’s detection engines flagged it as malicious, confirming the phishing nature.
VirusTotal records show that 13 of 93 security vendors have flagged the domain, providing additional corroboration of malicious intent. The registrar listed is Sav.com, LLC, and the domain was originally registered on 25 June 1998, an unusually long lifespan for a phishing site, which may indicate reuse of legacy infrastructure. Gridinsoft assigns a trust score of 0 out of 100, and the domain appears on a single public blocklist, further reinforcing its unsafe status. PhishDestroy has explicitly blocked the domain, indicating that known anti‑phishing feeds already recognize it as a threat.
Nameservers are hosted on the centralnic.net network (ns1‑ns4.centralnic.net). Defenders should continue to block the IP address 178.16.53.103 and the domain gl.qxzqqp6.sa.com at perimeter and DNS layers, monitor for any re‑activation, and ensure that any outbound traffic to this host is logged and investigated. Given the lack of SSL and the placeholder page title, there is limited evidence of active credential‑harvesting pages, but the combination of multiple vendor detections, Safe Browsing flags, and low trust score warrants immediate preventive action. Continuous monitoring of associated IP ranges and the registrar’s new registrations is recommended to detect possible resurgence of malicious activity.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание