qantasrewards[.]915453[.]com
qantasrewards.915453.com — Контент недоступен (HTTP 502). Олицетворение бренда: Genericcloudflare; Тип мошенничества: Fake Airdrop. Сводка доказательств: VirusTotal 16/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, Cluster25, CRDF); URLScan malicious verdict; PhishDestroy score 95/100.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, qantasrewards.915453.com, was registered on February 21, 2026 and is currently reported as offline. Infrastructure analysis shows it resolves to the IP address 172.67.220.63, which belongs to the Cloudflare network (AS13335) located in the United States. The site’s TLS certificate is identified as WE1, indicating a standard Cloudflare‑issued certificate without additional validation. The domain has been flagged by the PhishDestroy blocklist and appears on a single external security blocklist, confirming that at least one protective service has taken action against it.
VirusTotal reports that 16 of 93 scanning engines have flagged the domain, reinforcing the suspicion of malicious activity. The Gridinsoft trust score of 0 out of 100 reflects a complete lack of confidence in the site’s legitimacy. The campaign is classified as a “Fake Airdrop” scam, targeting users with a generic phishing lure that mimics a rewards program. Because the site is already taken offline, immediate remediation consists of ensuring that network perimeter controls block the domain and its resolved IP, and that any cached DNS entries are purged.
Defenders should also monitor for additional sub‑domains under the 915453.com parent zone, as attackers frequently reuse the same registration holder for related campaigns. Continuous telemetry from endpoint and web‑gateway products should be tuned to alert on any future resolution of the IP 172.67.220.63 or on similar SSL certificate fingerprints. Given the elevated risk rating, organizations handling sensitive credential flows should treat any email or communication referencing “Qantas Rewards” with heightened scrutiny and verify the authenticity through official channels.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание