qafiro[.]online
“Reddit - The heart of the internet”
qafiro.online — Непроверенный. Сводка доказательств: VirusTotal 3/93 (CRDF, Gridinsoft, SOCRadar); PhishDestroy score 71/100. Регистратор: Go Daddy.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain qafiro.online was observed delivering a generic phishing payload and is currently listed as offline. Technical analysis shows that the domain resolved to the IP address 172.67.166.80, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. The hosting utilizes Cloudflare services, including HTTP/3 support, and the TLS certificate was issued by Google Trust Services under the WE1 hierarchy, indicating a valid HTTPS endpoint at the time of capture. Registration data reveals the domain was created on February 21, 2026 through Go Daddy, LLC, and the authoritative nameservers are cora.ns.cloudflare.com and salvador.ns.cloudflare.com.
An HTTP request returned a 200 status code, and the page title reported by the scanner was "Reddit - The heart of the internet," a title that does not correspond to the observed phishing behavior but may be used to disguise the payload. VirusTotal scanned the domain with 93 security vendors, of which three flagged it as malicious, and the domain appears on one external security blocklist. PhishDestroy has also recorded the domain as blocked.
While the presence of the Reddit‑related page title suggests an attempt to mimic a legitimate service, the specific phishing content, targeted credentials, and victim profile remain undocumented in the available intelligence. Defenders should treat qafiro.online as a confirmed phishing indicator: block the domain at network perimeter, add it to internal blacklists, monitor DNS queries for the associated IP and nameservers, and consider sinkholing traffic to prevent further credential harvesting. Ongoing observation of the IP address and Cloudflare infrastructure is advised, as the hosting environment may be reused for additional malicious campaigns.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Анализ VirusTotal
Анализ конфигурации сайта
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание