hf[.]onewaybanner[.]sa[.]com
“Site is created successfully!”
Сводка доказательств
Analysis as of July 24, 2026 indicates that the domain hf.onewaybanner.sa.com is currently offline but was previously resolved to the IPv4 address 178.16.53.103 located in the Netherlands and assigned to AS202412 (Omegatech LTD). The authoritative name servers are ns1.centralnic.net through ns4.centralnic.net, and the domain was registered through Sav.com, LLC on June 25, 1998. No TLS certificate was observed, meaning the site operated without HTTPS. The only publicly visible page title retrieved before takedown was “Site is created successfully!”, which does not reveal a target brand or specific service. Google Safe Browsing classifies the URL as a social engineering threat, and the domain appears on the PhishDestroy blocklist.
VirusTotal reports that 13 of 93 scanners flagged the domain, indicating a moderate level of detection across anti‑malware engines. Gridinsoft assigns a trust score of 0 out of 100, reinforcing the malicious assessment. The domain is listed on one additional security blocklist, further confirming its abuse. While the exact phishing campaign or impersonated brand cannot be identified from the available data, the combination of social‑engineering labeling, multiple vendor detections, and a zero trust score suggest that the site was used to lure victims into disclosing credentials or personal information.
Defenders should add hf.onewaybanner.sa.com to URL filtering, DNS sinkhole, and endpoint blocklists, monitor for any future resolution to new IPs, and consider scanning internal logs for prior connections to the IPv4 address 178.16.53.103. Because the domain lacks HTTPS, any traffic to it would have been unencrypted, simplifying credential capture. Continuous threat‑intel feeds should be consulted for updates, and incident response teams should treat any observed traffic as potentially compromised.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 12.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание