gl[.]nqoxur2[.]sa[.]com
“Site is created successfully!”
Зведення доказів
gl.nqoxur2.sa.com was observed by multiple threat intelligence sources as a generic phishing infrastructure. The domain resolves to the IPv4 address 178.16.53.103, which is registered to AS202412 Omegatech LTD and geolocated to the Netherlands. Registration data shows the domain was created on 25 June 1998 through the registrar Sav.com, LLC, and is served by the four centralnic.net nameservers. No TLS certificate is present; the site is accessible only via HTTP, which further reduces trust.
The Gridinsoft trust score is 0 out of 100, indicating a lack of reputation. VirusTotal analysis recorded eight detections out of ninety‑three scanned engines, and the domain is listed on one external blocklist and has been explicitly blocked by the PhishDestroy service. The only visible page title returned by the HTTP response is “Site is created successfully!”, a generic message that provides no insight into the phishing payload or targeted brand. The current host status is reported as offline, suggesting the site has been taken down or is temporarily unavailable.
Available evidence confirms the domain’s association with phishing activity, but the exact content and victim targeting remain unknown because no page content has been captured beyond the title. Analysts should continue to monitor the IP address 178.16.53.103 for re‑hosting of malicious pages and enforce network‑level blocks for both the domain and its host. Adding the domain to internal URL filtering lists, updating intrusion detection signatures, and sharing the indicator set with upstream threat‑sharing communities are recommended mitigation steps. Given the low trust score, lack of encryption, and multiple vendor detections, the domain should be treated as high‑risk until a definitive takedown confirmation is obtained.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 13.08.2026
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога