DANGEROUS

Critical risk detected

21 of 91 antivirus engines flag this page as malicious. Our security stack flagged multiple threat indicators on this website. Don't enter personal information, deposit money, or download files.

Security Review

Is pre.sequareeus.online legit or a scam?

Our verdict:Dangerous· 1/100

Vidar malware botnet C2 domain flagged malicious by 21 antivirus engines including BitDefender and CyRadar, plus threat feeds.

pre.sequareeus.onlineScanned 40d ago
0
Trust score
DANGEROUS
Heuristics 0·MT 0
Category tags
malware#Malware100% MT confidence
Technical red flags (1)

These checks passed — but they don't clear the site. A clean antivirus result, valid SSL, and a calm server only mean it isn't hosting malware; they say nothing about whether the business is real. This verdict is based on the site's conduct and content, not a malware detection.

View density

Analysis Summary

Threat Intelligence
0/91
Engines flagged this URL
Domain Age
Registration date unknown
MT Intelligence
Dangerous
Critical likelihood · 100% confidence

MT Intelligence

Advanced threat intelligence
MT Security Analyst
Critical scam likelihoodengineMT · Guardiantrust0/100
MT AgentLive web researchVisual inspectionNetwork correlation
0%
Confidence
The site pre.sequareeus.online is a command and control server for Vidar stealer malware used in botnets. Our antivirus network detected it with 21 out of 91 engines flagging malicious, including BitDefender, CyRadar, and AlphaSOC. Threat intelligence confirms associations with Vidar across multiple sequareeus.online subdomains. No positive signals outweigh these red flags, despite clean browser blocklists and IP reputation. This drives our malicious verdict with full confidence.
Full dossier
Analysis complete

Page Content

  • No functional page content; associated purely with malware operations.
  • Redirects show 1 hop with no suspicious homoglyphs or IDN tricks.

Infrastructure

  • Hosted on IP 104.21.19.141 with clean abuse score but tied to Vidar via Cloudflare.
  • Valid SSL from Google Trust Services, expires in 37 days.
  • WHOIS data unavailable.

Domain History

  • Global traffic index shows not indexed, indicating low legitimate use.
  • Multiple subdomains like brd.sequareeus.online linked to same malware family.

Web Reputation

  • 5 scam reports tie it to Vidar botnet C2; no positive reviews or business registration.
  • Clean on browser blocklists and sandbox, but AV detections dominate.
Risk Factors
7
  • 21 out of 91 antivirus engines flag it malicious, including BitDefender, CyRadar, and AlphaSOC.
  • Threat intelligence lists it as Vidar botnet C2 server on ThreatFox, SecureFeed, and SOCDefenders.
  • Multiple sequareeus.online subdomains associated with Vidar malware operations.
  • Malware samples in analysis contact this domain.
  • Facebook post flags sequareeus.online as potential card scam.
  • No business registration or positive reviews found.
  • Not indexed in global traffic rankings.
Positive Signals
3
  • Browser blocklist feeds show clean.
  • Sandbox analysis gave it a score of 0 with no flags.
  • Hosting IP has 0 abuse reports and clean reputation score.
AI Recommendation
Do not visit this domain under any circumstances—it controls malware infections. Report it to your antivirus and block it in your browser or hosts file.
Scam network detected
5 linked domains correlated

Multiple subdomains of sequareeus.online flagged in threat feeds as Vidar C2 infrastructure.

brd.sequareeus.onlineqhl.sequareeus.onlinewsp.sequareeus.onlinetub.sequareeus.onlinesequareeus.online
Next-gen fraud intelligence
Evidence-backedCross-checked

Website Preview

Screenshot of pre.sequareeus.online
LIVE RENDER
pre.sequareeus.online

Automated page render — captured in a safe sandbox. What an ordinary visitor would see when loading the site.

Web Research Findings

Our live research agent queries scam-report databases, consumer-review sites, news coverage, and general web search for pre.sequareeus.online, then cross-checks business-registration records and look-alike domain patterns. Everything below is pulled from what it actually found.

Business registration
No public record found
Could not match the site to a registered company — common for small sites.
Clone check
Not a clone
No well-known site's layout or branding detected here.
Typosquat check
No look-alike match
The domain doesn't resemble any well-known brand's spelling.
Web mentions
5 scam reports
Key findings
6 headline facts from open-web research
  • pre.sequareeus.online flagged as domain IOC on ThreatFox for Vidar botnet C2 server.
  • Classified as malicious host by SecureFeed due to Vidar association.
  • Multiple sequareeus.online subdomains (brd., qhl., wsp., tub.) listed in threat feeds as Vidar C2.
  • Malware samples in Hybrid Analysis contact pre.sequareeus.online.
  • Featured in Pointwild report on Vidar stealer operations via Cloudflare.
  • Facebook post questions sequareeus.online as potential scam for card services.
Scam reports (5)
Direct quotes from public scam databases, forums, and news.
  • ThreatFoxopen

    "IOC Type : domain. Threat Type : botnet_cc. Malware: Vidar. Confidence Level : Confidence level is high (100%)."

  • SecureFeedopen

    "Classification: malicious. Hostname: pre.sequareeus.online. EntityType: Host. Malicious Tags: malicious."

  • SOCDefendersopen

    "The domain pre.sequareeus.online is associated with the Vidar malware family, specifically functioning as a command and control (C2) server for a botnet."

  • Pointwildopen

    "sequareeus[.]online is routed through Cloudflare infrastructure (IP: 104.21.19.141), which appears to function as an intermediary layer between the victim"

  • Facebookopen

    "ata ki dual crunce card naki scam https://sequareeus.online/user/dashboard"

Research summary
Narrative write-up from our AI analyst, grounded on the facts above
Our research uncovered 5 reports linking pre.sequareeus.online to Vidar malware as a botnet C2 server, from ThreatFox, SecureFeed, SOCDefenders, and Pointwild. Malware samples connect to it, and subdomains like brd.sequareeus.online share the pattern. A Facebook post calls sequareeus.online a potential scam for card services. No positive reviews, complaints beyond malware, or business registration found.

Antivirus Engines

Detection matrix · live
22 engines flagged this URL

We cross-check every URL against our antivirus network of 91 malware and blacklist engines. Each detection is listed below by engine name — even a single hit is a meaningful signal.

21Malicious1Suspicious43Harmless91Engines
0
of 91
ADMINUSLabs
Malicious· malicious
AlphaSOC
Malicious· malware
BitDefender
Malicious· malware
Chong Lua Dao
Malicious· malicious
CRDF
Malicious· malicious
CyRadar
Malicious· malware
Dr.Web
Malicious· malicious
ESET
Malicious· malware
Forcepoint ThreatSeeker
Malicious· malicious
Fortinet
Malicious· malware
G-Data
Malicious· malware
Kaspersky
Malicious· phishing
LevelBlue
Malicious· phishing
Lionic
Malicious· malware
MalwareURL
Malicious· malware
Rising
Malicious· malicious
Seclookup
Malicious· malicious
SOCRadar
Malicious· malicious
Sophos
Malicious· phishing
VIPRE
Malicious· malware
Webroot
Malicious· malicious
Certego
Suspicious· suspicious

22 antivirus engines flagged this URL. Even a single detection is a meaningful signal — treat this site with extra caution and avoid entering credentials, payment info, or downloading any files.

Security Scans

Blacklist Check
Not flagged on major threat lists

Checked against the major public blocklists used by browsers and security tools — no hits.

Sandbox Render
Page rendered in a safe sandbox
Requests made0
Unique IPs0
Countries1
Detected brandsNone

Domain & Encryption

Encryption Certificate
StatusValid
ProtocolTLSv1.3
IssuerGoogle Trust Services · WE1
ExpiresJun 3, 2026 (37d)
Self-signedNo
Hosting & Technology
HostingCloudflare, Inc.
Server locationUS

Redirect Chain

Hops
1
Cross-domain
No
Lookalike
No
Punycode
No
  • 1301http://pre.sequareeus.online/
  • 2404https://pre.sequareeus.online/

Server Reputation

Hosting
CountryUnknown
NetworkCLOUDFLARENET - Cloudflare, Inc., US
IP address104.21.19.141
Abuse Intelligence
Confidence score0%
Reports on file0
ISPCloudflare, Inc.
Usage typeContent Delivery Network

Scam-Type Likelihood

1 scam-type patterns detected
Scam-Type Likelihood

0 of 13 categories showed signals

We check every URL against 13 distinct scam categories so the verdict tells you not just how risky the page is, but what kind of risk it carries. Each meter pulls from page signals, web reports, our AI analyst, vision, and the scam-network cluster — not from raw AV labels.

Top match: Malware
Malware
Low-level signals
0/100
  • AI analyst tagged this as malware / drive-by / cracked app.

Malware distribution detected

Signals suggest this page may deliver malicious files or exploit the browser.

  • Do not interact with pre.sequareeus.online

    Do not enter credentials, deposit money, download files, or install browser extensions from this site.

  • If you downloaded or ran a file from here

    Disconnect the device from the internet, run a full scan with a reputable antivirus (Malwarebytes, ESET, Bitdefender), and consider a second-opinion scanner. Change passwords on any account you used from the device afterwards — ideally from a different device.

  • Get free cleanup help

    MalwareTips has a dedicated malware-removal team who walk you through cleanup one-on-one.

    Open

Reputation Sources

How this domain rates across independent threat-intelligence and blocklist providers.

Google Safe Browsing
Not listedCheck ↗
VirusTotal
ListedCheck ↗
AbuseIPDB
Not listedCheck ↗

Safety FAQ

Common questions about this site, answered from the scan data on this page. These are auto-generated — not hand-written — so they always match the underlying report.

  • Our automated security review flags pre.sequareeus.online as dangerous. Multiple threat indicators were detected — treat the site as a scam until proven otherwise.

Final Verdict

0
Trust / 100
Final Verdict·pre.sequareeus.online
DANGEROUS

This domain serves as a command and control server for the Vidar malware botnet. Our antivirus network shows 21 out of 91 engines flagging it as malicious, confirmed by multiple threat intelligence reports. Avoid it completely and do not visit or interact.

Do not visit this domain under any circumstances—it controls malware infections. Report it to your antivirus and block it in your browser or hosts file.

AV engines
91
MT passes
2
Net signals
0
Scan another URL
Security review completemalwaretips.com/url-scan
Recently scanned

Other Dangerous reports

Browse all reports
Community review

User reviews & comments(0)

Share your experience — "Lost $200 on a fake checkout" is more useful than "Scam". Your review helps others avoid traps.

Loading…
Loading comments…
Scanned by
harlan4096Staff
This report is generated automatically by combining threat intelligence, domain signals, and an AI security analyst. It is informational, not legal advice. Always use your own judgement before sharing personal information or money online.