mrel[.]pro
فحص التصيد والأمان للنطاق mrel.pro
“Horaire”
mrel.pro — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Mondialrelay; نوع الاحتيال: Generic Phishing. ملخص الأدلة: VirusTotal 12/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 86/100. مسجّل النطاق: NiceNIC.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
This domain, mrel.pro, is identified as a phishing site designed to mimic legitimate scheduling or timekeeping services, as suggested by its page title 'Horaire,' which translates to 'schedule' in French. The site poses a direct threat to users by attempting to harvest login credentials, personal information, or financial details through deceptive forms or fake login portals. Phishing sites like this often employ social engineering tactics, such as urgent requests or official-looking interfaces, to trick visitors into disclosing sensitive data. The risk is elevated due to the domain's sophisticated infrastructure and the use of evasion techniques to avoid detection. Analysis indicates that mrel.pro is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with high-risk domains. The domain resolves to the IP address 188.114.96.3 and is flagged by 12 out of 95 security vendors on VirusTotal, a clear indicator of malicious activity. Additionally, the domain appears on at least one security blocklist and has been assigned a trust score of 0/100 by Gridinsoft, further confirming its fraudulent nature. The site employs technologies such as Plesk, Node.js, Phusion Passenger, Express, and Cloudflare, which are often leveraged to obfuscate malicious activity and enhance the site's resilience against takedowns. The use of HTTP/3 and Cloudflare Browser Insights suggests an attempt to appear legitimate while masking its true intent. If you have visited mrel.pro or interacted with its content, immediate action is required to mitigate potential risks. First, disconnect the device used to access the site from any networks to prevent further data exfiltration. Run a full system scan using updated antivirus or anti-malware software to detect and remove any malicious payloads. If you entered any credentials or personal information, change those details immediately on the legitimate platforms they pertain to, and enable multi-factor authentication where possible. Monitor your accounts for unauthorized activity and consider reporting the incident to relevant cybersecurity authorities or your organization's IT security team. Avoid clicking on any links or downloading attachments from suspicious emails or messages, as these may be part of a broader phishing campaign.
استخبارات أمن الشبكات Registrar context
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-08 04:43:04 UTC
التقنيات · 7 identified
Plesk is a web hosting and server data centre automation software with a control panel developed for Linux and Windows-based retail hosting service providers.
www.plesk.com ثقة 100٪Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org ثقة 100٪Phusion Passenger is a free web server and application server with support for Ruby, Python and Node.js.
phusionpassenger.com ثقة 100٪Express is a web application framework for Node.js, released as free and open-source software under the MIT License. It is designed for building web applications and APIs.
expressjs.com ثقة 100٪Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com ثقة 100٪Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of mrel.pro · checked Jun 26, 2026
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب