qafiro[.]online
“Reddit - The heart of the internet”
Kanıt özeti
The domain qafiro.online was observed delivering a generic phishing payload and is currently listed as offline. Technical analysis shows that the domain resolved to the IP address 172.67.166.80, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. The hosting utilizes Cloudflare services, including HTTP/3 support, and the TLS certificate was issued by Google Trust Services under the WE1 hierarchy, indicating a valid HTTPS endpoint at the time of capture. Registration data reveals the domain was created on February 21, 2026 through Go Daddy, LLC, and the authoritative nameservers are cora.ns.cloudflare.com and salvador.ns.cloudflare.com.
An HTTP request returned a 200 status code, and the page title reported by the scanner was "Reddit - The heart of the internet," a title that does not correspond to the observed phishing behavior but may be used to disguise the payload. VirusTotal scanned the domain with 93 security vendors, of which three flagged it as malicious, and the domain appears on one external security blocklist. PhishDestroy has also recorded the domain as blocked.
While the presence of the Reddit‑related page title suggests an attempt to mimic a legitimate service, the specific phishing content, targeted credentials, and victim profile remain undocumented in the available intelligence. Defenders should treat qafiro.online as a confirmed phishing indicator: block the domain at network perimeter, add it to internal blacklists, monitor DNS queries for the associated IP and nameservers, and consider sinkholing traffic to prevent further credential harvesting. Ongoing observation of the IP address and Cloudflare infrastructure is advised, as the hosting environment may be reused for additional malicious campaigns.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 12.08.2026
Tespit zaman çizelgesi
-
Alan adı durumu
Erişilebilir → Erişilemiyor
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
-
Alan adı durumu
Erişilemiyor → Erişilebilir
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin