Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
It contains 9 outgoing records; the latest is dated . The recorded recipient is domainabuse@tucows.com.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
nemurex[.]com
Análisis de phishing y seguridad de nemurex.com
“Nemurex: Most Popular Online Crypto Casino Based on Blockchain”
nemurex.com — Accesible · acceso restringido (HTTP 403). Suplantación de marca: Genericcrypto; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 14/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Fortinet); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 92/100. Registrador: Tucows.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, nemurex.com, poses a high-risk brand impersonation threat targeting users of cryptocurrency-based gambling platforms. Analysis indicates the domain mimics a legitimate blockchain casino, presenting itself as "Nemurex: Most Popular Online Crypto Casino Based on Blockchain" to deceive visitors into disclosing login credentials, depositing cryptocurrency, or installing malicious software. The fraudulent nature of this operation is underscored by its attempt to exploit the growing popularity of decentralized gambling platforms, which often lack centralized oversight, making them attractive targets for threat actors. Infrastructure analysis reveals multiple technical indicators supporting the malicious classification of nemurex.com. The domain was registered on August 28, 2025, through Tucows Domains Inc., a registrar frequently utilized by both legitimate and malicious entities. It resolves to the IP address 104.21.77.69, hosted on Cloudflare's network (AS13335), a common obfuscation tactic to conceal the true origin of phishing infrastructure. Security vendors have flagged the domain in 14 out of 95 VirusTotal scans, while it appears on three distinct security blocklists. The SSL certificate, issued by Google Trust Services (WE1), further mimics legitimacy, though this is a routine tactic in phishing campaigns to evade browser-based warnings. Users who visited nemurex.com should take immediate remedial actions to mitigate potential compromise. Any credentials, cryptocurrency wallet addresses, or personal information entered on the site should be considered exposed. Affected individuals are advised to revoke access to any linked accounts, monitor for unauthorized transactions, and conduct a thorough review of connected devices for malware. Given the domain's association with cryptocurrency fraud, victims should also report the incident to relevant financial and cybersecurity authorities. The domain's current offline status does not preclude future reactivation; users are urged to remain vigilant against similar impersonation attempts targeting blockchain-based gambling platforms.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Historial de denuncias de abuso · 9 stored reports over 70 days · click to expand
-
Report #1 Feb 26, 2026 · 18:56 UTCPhishing Abuse Report: nemurex[.]comdomainabuse@tucows.com
-
Report #2 ICANN CC 150h still active Mar 5, 2026 · 01:41 UTCESCALATION #2 (150h active): Phishing - nemurex[.]comdomainabuse@tucows.com abuse@verisign-grs.com compliance@icann.org
-
Report #3 ICANN CC 184h still active Mar 6, 2026 · 11:03 UTCESCALATION #3 (184h active): Phishing - nemurex[.]comdomainabuse@tucows.com abuse@verisign-grs.com compliance@icann.org
-
Report #4 ICANN CC 436h still active Mar 16, 2026 · 23:36 UTCESCALATION #4 (436h active): Phishing - nemurex[.]comdomainabuse@tucows.com abuse@verisign-grs.com compliance@icann.org
-
Report #5 ICANN CC 1264h still active Apr 20, 2026 · 14:47 UTCESCALATION #5 (1264h active): Phishing - nemurex[.]comdomainabuse@tucows.com abuse@verisign-grs.com compliance@icann.org
-
Report #6 ICANN CC 1318h still active Apr 22, 2026 · 20:20 UTCESCALATION #6 (1318h active): Phishing - nemurex[.]comdomainabuse@tucows.com abuse@verisign-grs.com compliance@icann.org
-
Report #7 ICANN CC 1411h still active Apr 26, 2026 · 17:09 UTCESCALATION #7 (1411h active): Phishing - nemurex[.]comdomainabuse@tucows.com abuse@verisign-grs.com compliance@icann.org
-
Report #8 ICANN CC 1460h still active Apr 28, 2026 · 18:19 UTCESCALATION #8 (1460h active): Phishing - nemurex[.]comdomainabuse@tucows.com abuse@verisign-grs.com compliance@icann.org
-
Report #9 ICANN CC 1659h still active May 7, 2026 · 01:20 UTCESCALATION #9 (1659h active): Phishing - nemurex[.]comdomainabuse@tucows.com abuse@verisign-grs.com compliance@icann.org
Análisis de VirusTotal
Evidencias archivadas
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of nemurex.com · checked Mar 2, 2026
Datos y informes externos
PD-1772674913-nemurex.com Recipient: domainabuse@tucows.com ¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.