MALICIOUS — HIGH
test[.]mspfos1[.]sa[.]com
The domain test.mspfos1.sa.com was registered through Sav.com, LLC and has a creation timestamp of June 25, 1998.
- VirusTotal
- 5/93
- Blocklists
- No stored match
- Доступность
- Контент недоступен · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
test.mspfos1.sa.com — Контент недоступен (HTTP 502). Сводка доказательств: VirusTotal 5/93 (alphaMountain.ai, CRDF, CyRadar, Fortinet, Gridinsoft); PhishDestroy score 65/100. Регистратор: Sav.com.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Analysis
The domain test.mspfos1.sa.com was registered through Sav.com, LLC and has a creation timestamp of June 25, 1998. DNS resolution points to the IPv4 address 178.16.53.103, which is allocated to AS202412 owned by Omegatech LTD in the Netherlands. The authoritative name servers are ns1.centralnic.net, ns2.centralnic.net, ns3.centralnic.net, and ns4.centralnic.net. No TLS certificate is presented for the host, indicating that the site operates only over plain HTTP.
A HTTP request returns a page whose title is "Site is created successfully!", suggesting a generic success message rather than a targeted brand page. The domain is currently taken offline, but historical data shows it was flagged by PhishDestroy and appears on a single security blocklist. Gridinsoft assigned a trust score of 0 out of 100, reflecting a highly untrusted reputation. VirusTotal analysis shows that five of ninety‑three commercial scanning engines marked the domain as malicious, reinforcing the suspicion of abusive activity.
The limited detection count and the solitary blocklist entry suggest that visibility may be low, but the combination of a zero‑trust score, lack of encryption, and the generic success page title are consistent with a phishing infrastructure. Defenders should add the IP address 178.16.53.103 to outbound and inbound deny lists, monitor DNS queries for the domain and its name servers, and ensure web proxies block any HTTP traffic to the host. Continuous re‑scanning on VirusTotal and similar aggregators is advised to capture any changes in detection coverage. Because the site is offline, threat actors may reactivate it, so periodic verification of its status is recommended.
Охват данных12 recorded checks
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.