gl[.]nqoxur2[.]sa[.]com
“Site is created successfully!”
Kanıt özeti
gl.nqoxur2.sa.com was observed by multiple threat intelligence sources as a generic phishing infrastructure. The domain resolves to the IPv4 address 178.16.53.103, which is registered to AS202412 Omegatech LTD and geolocated to the Netherlands. Registration data shows the domain was created on 25 June 1998 through the registrar Sav.com, LLC, and is served by the four centralnic.net nameservers. No TLS certificate is present; the site is accessible only via HTTP, which further reduces trust.
The Gridinsoft trust score is 0 out of 100, indicating a lack of reputation. VirusTotal analysis recorded eight detections out of ninety‑three scanned engines, and the domain is listed on one external blocklist and has been explicitly blocked by the PhishDestroy service. The only visible page title returned by the HTTP response is “Site is created successfully!”, a generic message that provides no insight into the phishing payload or targeted brand. The current host status is reported as offline, suggesting the site has been taken down or is temporarily unavailable.
Available evidence confirms the domain’s association with phishing activity, but the exact content and victim targeting remain unknown because no page content has been captured beyond the title. Analysts should continue to monitor the IP address 178.16.53.103 for re‑hosting of malicious pages and enforce network‑level blocks for both the domain and its host. Adding the domain to internal URL filtering lists, updating intrusion detection signatures, and sharing the indicator set with upstream threat‑sharing communities are recommended mitigation steps. Given the low trust score, lack of encryption, and multiple vendor detections, the domain should be treated as high‑risk until a definitive takedown confirmation is obtained.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 12.08.2026
Tespit zaman çizelgesi
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin