nupuni[.]xyz
“Messenger”
nupuni.xyz — مغطى بعباءة · يمكن الوصول إليه. نوع الاحتيال: Generic Phishing. ملخص الأدلة: VirusTotal 6/91 (Fortinet, LevelBlue, Webroot); Spamhaus DBL_PHISH; cloaking observed; PhishDestroy score 98/100. مسجّل النطاق: NiceNIC.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of nupuni.xyz, observed as offline as of July 24, 2026, indicates that the domain was created on June 16, 2026 and is currently pointing to the Cloudflare edge IP 104.21.11.44 (AS13335, United States). The authoritative name servers are lauryn.ns.cloudflare.com and leland.ns.cloudflare.com, confirming that the domain is hosted behind Cloudflare's CDN. The TLS certificate presented is a Let's Encrypt certificate issued to the domain (subject identifier YE1), which is typical for fast‑deployed malicious sites. The only visible page title returned before takedown was “Messenger”, suggesting an attempt to lure users into messaging‑related credential harvesting, although the page content has not been captured. The domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar that is frequently seen in malicious registrations.
Gridinsoft assigned a trust score of 0 out of 100, indicating an extremely low reputation. The domain appears on a single security blocklist and has been actively blocked by the PhishDestroy sinkhole, confirming that at least one anti‑phishing platform has taken remediation action. VirusTotal scans show that six of ninety‑one scanning engines flagged the domain, reinforcing the malicious classification despite the low detection count. Uncertainties remain regarding the exact phishing kit used, the target brand, and any payload delivery mechanisms, because no further page content or network traffic has been published. The short lifespan (creation less than six weeks before takedown) limits the amount of observable activity, and the use of Cloudflare obscures the true origin of the hosting server.
Defenders should immediately add nupuni.xyz to internal DNS blocklists and URL filtering policies. Because the domain resolves to a shared Cloudflare IP, blocking the IP address may affect legitimate services; instead, rule sets should target the specific domain name.
استخبارات أمن الشبكات Registrar context
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-12 03:16:22 UTC
تحليل VirusTotal
الأدلة والتقارير الخارجية
PD-20260620-683688 Recipient: abuse@gen.xyz هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب