Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is netabuse@as20068.net.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
niurengu[.]com
“Online Customer Service - Visitor”
niurengu.com — असत्यापित. साक्ष्य सारांश: VirusTotal 4/91 (alphaMountain.ai, Gridinsoft, LevelBlue, SOCRadar); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 83/100. रजिस्ट्रार: Gname 049.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
niurengu.com is currently flagged as a high‑risk generic phishing site. The domain was registered on March 28, 2026 through Gname 049 Inc and remains active. Its risk rating is high, reflecting the presence of credential‑stealing infrastructure targeting users of popular services.
Infrastructure analysis shows the domain resolves to the IPv4 address 198.252.106.21, hosted in the United States by Hawk Host Inc. The web server is identified as Nginx with HTTP Strict Transport Security enabled, and the site presents a valid Let’s Encrypt SSL certificate. Authoritative name servers are dm1.longmingdns.com and dm2.longmingdns.com, indicating use of a third‑party DNS provider.
Threat intelligence sources place niurengu.com on three security blocklists and record it as blocked by PhishDestroy, MetaMask, and SEAL. AlienVault OTX references the domain in two separate threat‑intel pulses, reinforcing its association with phishing campaigns. Despite a clean VirusTotal scan (0/95 detections), the multiple blocklist entries and high‑risk rating suggest active malicious use.
Defenders should treat niurengu.com as hostile. Immediate actions include adding the domain and its resolving IP 198.252.106.21 to deny‑list rules, monitoring DNS queries for the associated name servers, and employing URL filtering to prevent user access. Continuous observation of any changes to the SSL certificate or hosting provider is advised to detect potential re‑deployment.
The presence of HSTS indicates an attempt to enforce secure connections, yet the underlying credential‑harvesting pages remain unverified. The combination of a newly created domain, rapid deployment of a valid TLS certificate, and inclusion in multiple blocklists aligns with known phishing kit deployment patterns. Ongoing reconnaissance should track any new payloads or redirects associated with the site.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
तकनीकें · 2 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% विश्वासHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% विश्वासवायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of niurengu.com · checked Jul 12, 2026
साइट कॉन्फ़िगरेशन विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
PD-20260712-6A6A6A Recipient: netabuse@as20068.net क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।