notinretardeducation[.]run
notinretardeducation.run — Contenido no disponible (HTTP 502). Resumen de las pruebas: VirusTotal 1/93 (SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Registrador: PDR.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of the domain notinretardeducation.run shows a recent creation date of February 27, 2026 and immediate association with malicious activity. The domain resolves to IP address 172.67.141.23, which belongs to AS13335 Cloudflare, Inc., located in the United States. No SSL certificate was observed, and the HTTP response presents the generic page title "Just a moment...", a pattern commonly used by Cloudflare challenge pages that can be abused to hide malicious content. The registrar listed is PDR Ltd. d/b/a PublicDomainRegistry.com, and the authoritative nameservers are audrey.ns.cloudflare.com and rohin.ns.cloudflare.com, confirming the Cloudflare hosting relationship.
Blocklist intelligence indicates that three independent security blocklists have listed the domain, with specific blocklists including PhishDestroy, MetaMask, and SEAL. VirusTotal analysis recorded a single positive detection out of 93 scanned vendors, reinforcing the suspicion of malicious intent. Additionally, Gridinsoft assigned a trust score of 0 out of 100, indicating a complete lack of confidence in the domain’s legitimacy.
The domain is currently taken offline, which limits immediate exposure but does not remove the underlying infrastructure or the risk of re‑activation. Defenders should continue to enforce blocklist rules that include notinretardeducation.run, monitor the associated IP 172.67.141.23 for any future activity, and consider adding the domain to internal blacklists. Given the absence of TLS, low trust scoring, and presence on multiple phishing‑focused blocklists, the domain should be treated as a high‑confidence phishing indicator until further evidence suggests remediation.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Inteligencia forense
Análisis de VirusTotal
Datos y informes externos
PD-20260227-4B8D9C Recipient: abuse@publicdomainregistry.com ¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.