qfssecurity[.]site
“QFS Ledger - Advanced Crypto Portfolio Tracking”
证据摘要
On 21 February 2026 the domain qfssecurity.site was registered. The domain resolves to the IPv4 address 64.29.17.65, which is allocated to Amazon.com, Inc. (AS16509) and geolocated in the United States. The TLS certificate presented by the site is identified as R10, indicating a low‑grade certificate. The page title returned from the HTTP response is “QFS Ledger – Advanced Crypto Portfolio Tracking”, suggesting an attempt to lure victims interested in cryptocurrency portfolio management. The domain is classified as a crypto‑related scam and is reported to impersonate the brand “across”.
VirusTotal analysis shows that one of ninety‑three scanning engines flagged the domain as malicious. Independent security aggregators have assigned a Gridinsoft trust score of zero out of one hundred, and four blocklist providers—PhishDestroy, Polkadot, Enkrypt and Codeesura—have listed the domain, confirming its presence on multiple threat‑intelligence feeds. The site is currently reported as offline, and it appears on four security blocklists. The limited evidence does not reveal the hosting infrastructure beyond the Amazon AS, nor does it disclose the registrar that issued the domain registration.
No additional payload or command‑and‑control indicators have been observed. Defenders should consider adding 64.29.17.65 to network‑level deny lists, enforce DNS filtering for qfssecurity.site, and monitor for any future re‑activation of the domain. Continuous monitoring of the associated IP range and the Amazon AS16509 blocklist entries is advised, as the attacker may migrate to adjacent addresses or recreate the domain under a different registrar. Organizations handling cryptocurrency assets should treat any unsolicited communications referencing “QFS Ledger” with heightened scrutiny, and users should be warned that the site is not affiliated with legitimate services.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
取证情报
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控