noreply[.]support-interne[.]org
“Phishing Simulation Notice”
Riepilogo delle prove
This domain, noreply.support-interne.org, is flagged as a generic phishing site designed to impersonate internal IT support communications. Analysis indicates it likely targets corporate users by spoofing official support notices, tricking victims into entering credentials or downloading malicious payloads under the guise of system updates or security alerts. The page title 'Phishing Simulation Notice' may be an attempt to deceive users into believing the interaction is part of a legitimate security training exercise, lowering their guard against the actual threat. Infrastructure analysis reveals multiple high-confidence indicators of malicious activity. The domain was registered on February 25, 2026, through Dynadot LLC, an uncommon timeline suggesting potential domain squatting or premeditated abuse. It resolves to IP address 20.50.64.14, hosted on Microsoft Corporation's AS8075 in Ireland, a pattern observed in other phishing campaigns leveraging cloud infrastructure for anonymity. Security vendors on VirusTotal detect the domain at 18/95, with one confirmed blocklist entry, including detection by enterprise-grade phishing prevention systems. The SSL certificate, issued by Let's Encrypt (R12), provides HTTPS encryption but does not validate legitimacy, a common tactic in phishing to evade browser warnings. Users who visited noreply.support-interne.org should assume potential exposure of credentials or device compromise. Immediate actions include revoking any entered passwords, particularly for corporate accounts, and scanning the device for malware using updated security tools. Network administrators should block the domain and its resolving IP at the perimeter and review logs for connections to 20.50.64.14. If the domain was accessed via a work device, report the incident to internal security teams for forensic analysis. Monitor accounts for unauthorized access and enable multi-factor authentication where available to mitigate further risk.
Istantanea delle prove inviate
- Inviato
- Voci del registro
- 1
- ID del caso
PD-20260225-F0C775- Titolo della pagina acquisita
- Phishing Simulation Notice
- Artefatto PDF
- Prova in PDF
Base giuridica
Testo completo delle prove
Policy Violations: Acceptable Use forbids illegal content; Spam & Abuse Policy prohibits phishing, fraud, malware; Dynadot may disable DNS and suspend domains
Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act
Data Coverage
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | noreply.support-interne.org |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 12/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
-
VirusTotal
18 → 20
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
ICANN OVERSIGHT
Registration: support-interne.org
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain support-interne.org behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of noreply.support-interne.org · checked Mar 2, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo