# PhishDestroy threat dossier — niurengu.com ================================================================ Fetched: 2026-07-30 16:11:19 UTC Canonical: https://phishdestroy.io/domain/niurengu.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 4/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Gridinsoft, LevelBlue, SOCRadar AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 198.252.106.21 (US, Los Angeles) ASN: AS20068 Hawk Host Inc. Hosting org: Hawk Host Inc Registrar: Gname 049 Inc Nameservers: dm1.longmingdns.com, dm2.longmingdns.com Registered: 2026-03-28 Expires: 2027-03-28 Page title: Online Customer Service - Visitor HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-09-11 Status: INVALID chain Fingerprint: adb2243355f0b97ad92f663a4d5717b1d2130da801553e47a66840fd20ca8a90 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-03-28 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-12 15:50:34 UTC (by PhishDestroy tracker) First reported: 2026-07-12 20:21:58 UTC (abuse notice filed) Last verified: 2026-07-30 16:20:35 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f5697-a6be-70c9-b5da-60f94196f9d5/ URLQuery: https://urlquery.net/report/66b34ef8-1ac7-45df-932f-79fdd9e1c517 Wayback Machine: https://web.archive.org/web/*/niurengu.com crt.sh CT logs: https://crt.sh/?q=%25.niurengu.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=niurengu.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/niurengu.com URLhaus: https://urlhaus.abuse.ch/host/niurengu.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-12 17:17:41 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] niurengu.com: Confirmed Phishing Site niurengu.com is currently flagged as a high‑risk generic phishing site. The domain was registered on March 28, 2026 through Gname 049 Inc and remains active. Its risk rating is high, reflecting the presence of credential‑stealing infrastructure targeting users of popular services. Infrastructure analysis shows the domain resolves to the IPv4 address 198.252.106.21, hosted in the United States by Hawk Host Inc. The web server is identified as Nginx with HTTP Strict Transport Security enabled, and the site presents a valid Let’s Encrypt SSL certificate. Authoritative name servers are dm1.longmingdns.com and dm2.longmingdns.com, indicating use of a third‑party DNS provider. Threat intelligence sources place niurengu.com on three security blocklists and record it as blocked by PhishDestroy, MetaMask, and SEAL. AlienVault OTX references the domain in two separate threat‑intel pulses, reinforcing its association with phishing campaigns. Despite a clean VirusTotal scan (0/95 detections), the multiple blocklist entries and high‑risk rating suggest active malicious use. Defenders should treat niurengu.com as hostile. Immediate actions include adding the domain and its resolving IP 198.252.106.21 to deny‑list rules, monitoring DNS queries for the associated name servers, and employing URL filtering to prevent user access. Continuous observation of any changes to the SSL certificate or hosting provider is advised to detect potential re‑deployment. The presence of HSTS indicates an attempt to enforce secure connections, yet the underlying credential‑harvesting pages remain unverified. The combination of a newly created domain, rapid deployment of a valid TLS certificate, and inclusion in multiple blocklists aligns with known phishing kit deployment patterns. Ongoing reconnaissance should track any new payloads or redirects associated with the site. [Updates since narrative was generated:] - VirusTotal detections: now 4/91 (narrative was written when count was lower) ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260712-6A6A6A TLS cert SHA-256: adb2243355f0b97ad92f663a4d5717b1d2130da801553e47a66840fd20ca8a90 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/niurengu.com/ JSON API: https://api.destroy.tools/v1/check?domain=niurengu.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,932 domains (83,630 alive under monitoring, 110,042 confirmed takedowns/dead). Site: https://phishdestroy.io