Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@namecheap.com.
The latest stored availability evidence still shows the domain reachable; 17 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
preview-strategynavigator[.]newton[.]tech
“Strategic Plan Navigator”
preview-strategynavigator.newton.tech — Неперевірений. Зведення доказів: VirusTotal 4/91 (CRDF, Gridinsoft, PhishFort, SOCRadar); PhishDestroy score 71/100. Реєстратор: Namecheap.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of preview-strategynavigator.newton.tech indicates this domain is actively involved in credential-phishing operations as of July 27, 2026. The domain was registered on June 10, 2025, through NAMECHEAP INC, a registrar frequently observed in phishing campaigns due to its accessibility and bulk registration options. Infrastructure analysis reveals the domain resolves to the IP address 216.150.16.193 and utilizes Azure DNS nameservers (ns1-09.azure-dns.com, ns2-09.azure-dns.net, ns3-09.azure-dns.org, ns4-09.azure-dns.info), a configuration that, while legitimate in enterprise contexts, is also exploited by threat actors to lend credibility to malicious domains. Detection data from VirusTotal shows 1 of 91 security vendors has flagged this domain, a modest but non-zero detection rate that aligns with early-stage or evasive phishing infrastructure.
Additionally, the domain appears on one security blocklist, further confirming its malicious classification by at least one threat intelligence provider. The domain remains active, and no evidence from the provided data indicates takedown or mitigation efforts. The specific content or targeted brand of the phishing page is not yet analyzed, as no page title, brand target, or scam kit details were provided. Defenders should treat this domain as high-risk and prioritize blocking both the domain and its resolving IP (216.150.16.193) at the network level.
Organizations using Azure DNS should audit their nameserver configurations to ensure no unauthorized domains are leveraging their infrastructure. Given the domain's age (over a year since registration) and continued activity, it is likely part of a persistent campaign rather than a short-lived operation. Further investigation into the IP's hosting history and associated domains may reveal additional related threats.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: newton.tech
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain newton.tech behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 6 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 100% впевненостіReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% впевненостіVercel is a cloud platform for static frontends and serverless functions.
vercel.com 100% впевненостіNext.js is a React framework for developing single page Javascript applications.
nextjs.org 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіАналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of preview-strategynavigator.newton.tech · checked Jul 27, 2026
Докази та зовнішні звіти
PD-20260727-26DDBD Recipient: abuse@namecheap.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога