norowex[.]com
“Suspected phishing site | Cloudflare”
संग्रहीत अवलोकन
देखा गया शीर्षक अंतर
साक्ष्य सारांश
Analysis of the domain norowex.com shows that it was registered on 21 February 2026 through Web Commerce Communications Limited and immediately pointed to Cloudflare’s network (nameservers lia.ns.cloudflare.com and yadiel.ns.cloudflare.com, IP 172.67.150.30, AS13335, United States). The TLS certificate is issued by Google Trust Services under the WE1 profile, indicating standard Cloudflare SSL termination. A HTTP GET returns a 403 status and the page title is “Suspected phishing site | Cloudflare”, which is a generic Cloudflare warning page rather than the original content. The site is classified as a Social Media Phishing campaign and the underlying kit has been identified as the “Gambler Scam” package.
VirusTotal scanning recorded 13 detections out of 93 security vendors, and the domain appears on a single external blocklist that has been integrated by PhishDestroy. Gridinsoft assigns a trust score of 1 / 100, reinforcing the malicious assessment. The domain is currently taken offline, but the infrastructure—Cloudflare front‑end, the same IP address and the registrar—remains usable for rapid re‑deployment. Uncertainty remains around the specific social media platform targeted and the exact payload delivered, as no content analysis beyond the Cloudflare warning page is available.
Defenders should block the domain and its associated IP at perimeter and DNS levels, monitor for re‑use of the same nameservers or IP range, and incorporate the indicator set (domain, IP, nameservers, SSL fingerprint) into threat‑intel feeds. Continuous re‑scanning on VirusTotal and other multi‑engine services is advised to capture any changes in detection ratios. Organizations that rely on social‑media authentication flows should enforce MFA and educate users about unsolicited login requests, as the campaign likely attempts credential harvesting.
Data Coverage
सुरक्षा संकेत
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 11/08/2026
पहचान समयरेखा
-
Cloudflare Radar
Cloudflare Radar स्कैन संग्रहीत · स्कैन खोलें
-
डोमेन स्थिति
पहुँच योग्य → पहुँच योग्य नहीं
-
Cloudflare Radar
Cloudflare Radar स्कैन संग्रहीत · स्कैन खोलें
-
डोमेन स्थिति
पहुँच योग्य नहीं → पहुँच योग्य
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणDNS, TLS नाम और समय-मुद्राएँ
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
वायरसटोटल विश्लेषण
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।