sandadata[.]com[.]ng
“Dankurmi Data | A technology platform that offers solutions to digital needs at best possible price…”
Сводка доказательств
Analysis indicates that sandadata.com.ng was registered on August 11, 2025 through HostAfrica and uses the nameservers dns1.webproserver.com and dns2.webproserver.com. The domain resolves to the IPv4 address 192.3.190.188, which is hosted by AS36352 (HostPapa) in the United States. No TLS certificate is presented, meaning the site is served over plain HTTP. The page title returned from the live host – “Dankurmi Data | A technology platform that offers solutions to digital needs at best possible price without compromising quality.
data, airtime, electricity, cable, airtime to cash, all available for” – does not reference the targeted brand, but the intelligence file classifies the activity as credential phishing that impersonates Google. VirusTotal records show that one of ninety‑five scanning engines flagged the domain, and the site appears on a single security blocklist. PhishDestroy has already taken the domain offline, and the Gridinsoft trust score is 0 out of 100, indicating a lack of reputation. The combination of a newly created domain, lack of encryption, low trust score, and a single vendor detection suggests a low‑volume, targeted impersonation campaign rather than a large‑scale operation.
Uncertainty remains around the actual phishing payload, the presence of any login form, and whether additional infrastructure such as command‑and‑control servers is associated with the IP address. Defenders should block the domain at perimeter filters, add the IP address 192.3.190.188 to deny‑list rules, and monitor for any DNS queries to the listed nameservers. Because the domain is already offline, ongoing threat hunting should focus on any recent credential submissions that reference Google credentials and on correlating user reports with the timeframe of the domain’s activity. Continuous review of host‑based detections for the AS36352 network may reveal further related campaigns.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 13.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание