Перейти до звіту про безпеку
⚠️
Цей домен було позначено як шкідливий
Системи безпеки повідомляють про виявлення: 8. Будьте дуже обережні — не вводьте облікові дані чи особисту інформацію.
Безпека домену та аналіз загроз

cpanel[.]qatarairways-contract[.]com

“cPanel Login”

Загрозливий вердикт Критичний 78/100 оцінка доказів
Доступність Неперевірений Поточна доступність не перевірена
Виявлення VirusTotal: 8/91 Тип шахрайства: Credential Phishing
09.05.2026
Огляд звіту

cpanel.qatarairways-contract.com — Неперевірений. Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 8/91 (alphaMountain.ai, BitDefender, CyRadar, Fortinet, G-Data); PhishDestroy score 78/100. Реєстратор: INWX.

Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.

Зведення доказів
КРИТИЧНИЙ
Посилання
7BD34C80
Оцінка
78/100

cpanel.qatarairways-contract.com is currently active and returns HTTP 200 responses. The domain was registered through INWX GmbH and resolves to the authoritative name servers ns19.truehostdns.com and ns20.truehostdns.com. It appears on one security blocklist and is listed as blocked by PhishDestroy, indicating that at least one mitigation service has taken action against it. VirusTotal scans have flagged the domain in eight out of ninety‑one AV engines, providing additional corroboration of malicious intent.

The combination of a high‑risk classification, active status, and detection by multiple independent sources suggests that the domain is being used for a generic phishing campaign, likely targeting users of Qatar Airways by exploiting the “cpanel” subdomain pattern to lend credibility. No public information about the underlying hosting IP, SSL certificate details, or page title is available in the supplied intelligence, leaving the exact content of the site unverified. Because the domain resolves and delivers HTTP content, it is capable of hosting malicious pages or redirecting victims to credential‑harvesting forms. Defenders should add the domain to firewall deny lists, DNS blocklists, and email filtering rules.

Continuous monitoring of the name servers and any changes to the DNS records is recommended, as attackers frequently pivot to new IP addresses while retaining the same domain. Incident response teams should also watch for related subdomains that share the same registrar or name‑server pair, as they may be part of the same infrastructure. The current evidence does not provide details on payloads or victim interaction, so further sandbox or manual analysis of the live page is required to confirm the phishing vector and to extract any indicators such as URLs, form fields, or embedded scripts.

VirusTotal
VirusTotal
8 det.
Сертифікат TLS
Let's Encrypt
Зафіксований статус
Неперевірений
PhishDestroy
DestroyList
У списку
Обсяг даних VirusTotal 8 / 91 URLQuery не перевірено PhishStats не перевірено OTX no community references CF Radar scan completed URLScan capture not submitted URLScan verdict висновок недоступний Блокування DNS не перевірено TLS valid certificate, 52d WHOIS not parsed Знімок екрана не зафіксовано Ланцюжок перенаправлень не досліджено

Процес реагування на загрози Pipeline

Відкриття
Checks
Reports
Доступність
6/8

Статус у публічних блоклистах

Аналітика доменів

Домен
Сервер / ASN LiteSpeed · AS30083 velia.net
Репутація IP abuse score 0/100 1 report checked 29.07.2026
IP-адреса 50.30.32.39 US
ГеолокаціяUS St Louis, US
МережаAS30083 · velia.net
Зворотний пошук IPviewdns.info → rapiddns.io →
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Вперше виявлено09.05.2026
Сервери іменns20.truehostdns.com
TLS Fingerprint
TLS Observationvalid from 17.06.2026scanned 30.07.2026
TLS SAN Domainsqatarairways-contract.com
Favicon Hash
ICANN OVERSIGHT Registration: qatarairways-contract.com

Акредитація та контекст RAA

Registrar accreditation and DNS abuse obligations

For the registrable domain qatarairways-contract.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Нічого не надсилається автоматично.
Технології · 2 identified
LiteSpeed
Web servers

LiteSpeed is a high-scalability web server.

litespeedtech.com 100% впевненості
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org 100% впевненості
Detected via Cloudflare Radar · Wappalyzer engine
Поскаржитися на цей домен Надішліть докази та допоможіть захистити інших

Аналіз VirusTotal

8 / 91 постачальників безпеки позначили цей домен
View on VT
Last analyzed
alphaMountain.ai
BitDefender
CyRadar
Fortinet
G-Data
«Касперський»
LevelBlue
SOCRadar

Докази та зовнішні звіти

Чи вплинув на вас цей сайт?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.

Європол
Знайдіть офіційний канал звітності для вашої країни ЄС
National police directory
Остерігайтеся шахраїв, які обіцяють повернути втрачені кошти! Злочинці можуть знову зв’язатися з жертвами, видаючи себе за слідчих, адвокатів або агентів із відновлення. Не сплачуйте авансових зборів і не діліться обліковими даними. Дізнайтеся більше про шахрайство у сфері відшкодування збитків →

Зверніться до місцевих органів влади

Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.

Довідник 97 країн
Чернетка за допомогою штучного інтелекту — деталі інциденту обробляються постачальником штучного інтелекту Перегляньте та подайте його самостійно

Перевірити будь-який домен

Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування

Сканувати зараз

Повідомити про фішинг

Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту

Повідомити

Потокова стрічка про загрози

Останні звіти про фішинг і помічені зміни доступності

Відстежувати

Будьте в курсі подій, дбайте про свою безпеку

Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога

Потокова стрічка про загрози Оскаржити це оголошення
HTML · IFRAME

Вбудувати цей звіт

Поділіться цією інформацією про загрози на своєму веб-сайті або в блозі

embed.html
<iframe
  src="https://phishdestroy.io/uk/embed/domain/cpanel.qatarairways-contract.com"
  title="PhishDestroy threat report for cpanel.qatarairways-contract.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Дуже щирий лист-подяка

Генератор сатиричних чернеток

Одержувач
Контекст зборів

Це сатирична чернетка. Суми зборів є оцінками; ми не стверджуємо, що вони точно стосуються цього домену.