gl[.]qxzqqp6[.]sa[.]com
“Site is created successfully!”
gl.qxzqqp6.sa.com — 内容不可用. 证据摘要: VirusTotal 13/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); Google Safe Browsing flagged; PhishDestroy score 89/100. 注册商: Sav.com.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of gl.qxzqqp6.sa.com indicates a high‑risk generic phishing infrastructure that is currently taken offline. The domain resolves to the IPv4 address 178.16.53.103, which is assigned to AS202412 operated by Omegatech LTD in the Netherlands. No TLS certificate is presented for the host, meaning all HTTP traffic would be unencrypted. The site title returned during the brief scan reads "Site is created successfully!", offering no substantive content and suggesting a placeholder or abandoned landing page. Google Safe Browsing classifies the domain under social engineering, and the platform’s detection engines flagged it as malicious, confirming the phishing nature.
VirusTotal records show that 13 of 93 security vendors have flagged the domain, providing additional corroboration of malicious intent. The registrar listed is Sav.com, LLC, and the domain was originally registered on 25 June 1998, an unusually long lifespan for a phishing site, which may indicate reuse of legacy infrastructure. Gridinsoft assigns a trust score of 0 out of 100, and the domain appears on a single public blocklist, further reinforcing its unsafe status. PhishDestroy has explicitly blocked the domain, indicating that known anti‑phishing feeds already recognize it as a threat.
Nameservers are hosted on the centralnic.net network (ns1‑ns4.centralnic.net). Defenders should continue to block the IP address 178.16.53.103 and the domain gl.qxzqqp6.sa.com at perimeter and DNS layers, monitor for any re‑activation, and ensure that any outbound traffic to this host is logged and investigated. Given the lack of SSL and the placeholder page title, there is limited evidence of active credential‑harvesting pages, but the combination of multiple vendor detections, Safe Browsing flags, and low trust score warrants immediate preventive action. Continuous monitoring of associated IP ranges and the registrar’s new registrations is recommended to detect possible resurgence of malicious activity.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。