app-varitionals[.]sa[.]com
“Variational Omni”
证据摘要
app-varitionals.sa.com is currently listed as an active generic phishing infrastructure. The domain resolves to 104.21.93.113 and is served through Cloudflare nameservers camilo.ns.cloudflare.com and sarah.ns.cloudflare.com, indicating use of a CDN for concealment. PhishDestroy has already blocked the domain and it appears on at least one external security blocklist. VirusTotal analysis shows that 2 of 95 scanning engines have flagged the domain, reinforcing the suspicion of malicious intent. No additional public intelligence such as Safe Browsing entries, OTX mentions, or SSL certificate details are available at this time. At present, no page title or brand targeting information has been published, so the specific lure employed by the site cannot be identified. The lack of publicly visible SSL certificate details also limits verification of potential spoofed domains. The limited detection footprint suggests that the site may be newly deployed or employing techniques to avoid widespread indexing. Because the domain is still active, defenders should proactively deny outbound connections to the resolved IP address and add the domain to local DNS blocklists. Monitoring of DNS queries for the domain and its associated nameservers can provide early warning of internal attempts to reach the site. Network traffic inspection should include detection of HTTP or HTTPS requests to the IP 104.21.93.113, and any credential submission to this host should be treated as compromised. Incident response teams should consider the domain as a high‑risk indicator and correlate any related phishing emails with the observed infrastructure. Continued observation of VirusTotal and other reputation services is recommended to capture any additional detections that may emerge as the campaign evolves.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
技术
识别出 3 项高置信度技术
VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of app-varitionals.sa.com · checked Jul 21, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控