nomine[.]ro
nomine.ro 网络钓鱼与安全检查
“Index of /”
nomine.ro — 最后已知的活跃状态 (HTTP 200). 品牌冒充:Google; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 16/94 (ADMINUSLabs, alphaMountain.ai, Cluster25, CRDF, CyRadar); URLQuery 3 alerts; URLScan malicious verdict; Google Safe Browsing flagged; PhishDestroy score 100/100. 注册商: TERON SYSTEMS SRL.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain nomine.ro, registered on April 14 2026 through TERON SYSTEMS SRL, resolves to the IPv4 address 195.20.203.130, which is geolocated to Romania and associated with the same registrar. Authoritative name servers ns1.teron.ro through ns4.teron.ro serve the zone, indicating that the infrastructure is fully hosted by the registrar’s network. The site presents an HTTP 200 response with the generic page title "Index of /" and is served by Nginx. A Let's Encrypt R13 certificate is active, confirming that TLS termination is correctly configured but offering no indication of malicious content.
Malware and URL scanning services have flagged the domain: sixteen of ninety‑four vendors on VirusTotal reported it as malicious, and the domain appears on a single security blocklist. PhishDestroy has explicitly blocked the host, and Google Safe Browsing classifies it as a social‑engineering threat, consistent with the recorded scam type of brand impersonation targeting Google. The domain’s MX record points to itself, a pattern often observed in phishing infrastructure to simplify email spoofing. Gridinsoft assigns a trust score of zero out of one hundred, reinforcing the low‑reputation assessment.
Although the site has been taken offline, the observable infrastructure—dedicated name servers, a self‑referencing MX, a valid TLS certificate, and multiple vendor detections—provides concrete evidence of a high‑risk, Google‑impersonation campaign. Defenders should continue to block the domain at network perimeters, add it to internal blocklists, monitor the associated IP for any resurgence of activity, and consider reporting the case to relevant threat‑intel sharing platforms. Ongoing vigilance is advised because the offline status may be temporary and the underlying infrastructure remains under the control of the threat actor.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 1 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of nomine.ro · checked Apr 14, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。