lg[.]qeymqo2[.]sa[.]com
“Site is created successfully!”
lg.qeymqo2.sa.com — Контент недоступний (HTTP 502). Зведення доказів: VirusTotal 10/93 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Fortinet); Google Safe Browsing flagged; PhishDestroy score 80/100. Реєстратор: Sav.com.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
On July 24, 2026, the domain lg.qeymqo2.sa.com was identified as a high‑risk generic phishing infrastructure that has been taken offline. The site returned the page title “Site is created successfully!” and did not present an SSL certificate, indicating that all communications were conducted over clear‑text HTTP. VirusTotal records show that 10 of 93 scanned security vendors flagged the domain, reflecting a moderate detection consensus. Gridinsoft assigned a trust score of 0 out of 100, and Google Safe Browsing classifies the URL as a social‑engineering threat.
The domain resolves to the IPv4 address 178.16.53.103, which is registered to AS202412 Omegatech LTD and geolocated to the Netherlands. Hosting evidence points to the registrar Sav.com, LLC, with the domain originally created on June 25, 1998. Authoritative name servers are ns1.centralnic.net through ns4.centralnic.net. The domain appears on a single public blocklist and has been specifically blocked by the PhishDestroy sinkhole.
No SSL certificate was observed, and the lack of encryption further reduces confidence in the site’s legitimacy. While the page title suggests a generic success message, no additional content analysis is available, leaving the exact phishing payload or targeted brand undefined. Defenders should continue to block the IP 178.16.53.103 and the associated name servers at the network perimeter, update URL filtering rules to include lg.qeymqo2.sa.com, and monitor for any re‑registration attempts. Given the high risk rating and the combination of vendor detections, trust‑score zero, and Safe Browsing flag, the domain should be treated as malicious until a formal takedown is confirmed.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога