df[.]ncxdyu2[.]sa[.]com
“Site is created successfully!”
Зведення доказів
Analysis as of July 25 2026 indicates that the domain df.ncxdyu2.sa.com is presently offline but retains indicators of a high‑risk generic phishing operation. The domain resolves to the IPv4 address 178.16.53.103, which is assigned to AS202412 owned by Omegatech LTD in the Netherlands. No TLS certificate is presented, meaning the site was served over HTTP only. The authoritative name servers are ns1.centralnic.net, ns2.centralnic.net, ns3.centralnic.net, and ns4.centralnic.net, all typical of the CentralNic registry. Registration was performed through Sav.com, LLC and the domain was originally created on 25 June 1998, suggesting a long‑standing registration that may have been repurposed for abuse.
Public intelligence sources flag the site as a generic phishing vector. Google Safe Browsing lists it under the “social engineering” category, and VirusTotal records show that 14 of 93 scanned security vendors flagged the domain as malicious. It appears on one external blocklist and has been actively blocked by the PhishDestroy service. Gridinsoft’s trust score is 0 out of 100, reinforcing the malicious assessment. The only visible page title retrieved during prior scans is “Site is created successfully!”, which provides no legitimate content and is consistent with a placeholder page often used in phishing kits.
While the domain is currently taken offline, the underlying infrastructure – the IP address, name server configuration, and lack of TLS – remains observable and could be re‑activated. Defenders should continue to block df.ncxdyu2.sa.com at network perimeters, update intrusion‑prevention signatures with the observed IP and name server set, and monitor for any resurgence of the domain or similar patterns from the same hosting provider. Additional investigation should focus on traffic logs for connections to 178.16.53.103 and on any credential harvesting activity that may have been associated with the “Site is created successfully!” page.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 12.08.2026
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога