New Registrations

SEUR phishing domains

Newly registered lookalikes - tracked daily


SEUR phishing domains

Newly registered lookalikes - tracked daily


Tracked (7d)
4
New (24h)
2
vs avg
—
Website
seur.com
About
AISpanish parcel lure - same parcel-delivery 'fee required' pattern as DHL / Correos, almost always SMS-launched.
TLDs
.guru (1) · .center (1) · .shop (1)
Countries
United StatesUnited States (3)

Recently registered domains — may be used for phishing. Screenshots show parking pages while domains warm up. Use for Threat Hunting or watchlists.

Last check (UTC) First seen (UTC) ▾ URL Screenshot Flags Details
2026-09-29 14:23 2026-09-29 14:23
https://seur.guru
Screenshot of seur.guru Details
2026-09-29 14:23 2026-09-29 14:23
https://seur.center
Screenshot of seur.center Details
2026-09-26 14:05 2026-09-26 14:05
https://seurestraps.shop
Screenshot of seurestraps.shop Details
2026-09-23 14:02 2026-09-23 14:02
https://seurskwjd.top
Screenshot of seurskwjd.top Details

Recently registered domains — may be used for phishing. Screenshots show parking pages while domains warm up. Use for Threat Hunting or watchlists.

URL Screenshot Details
https://seur.guru
Screenshot of seur.guru Details
https://seur.center
Screenshot of seur.center Details
https://seurestraps.shop
Screenshot of seurestraps.shop Details
https://seurskwjd.top
Screenshot of seurskwjd.top Details

AIHow to verify a real SEUR URL

  • Legitimate SEUR URLs always end in seur.com (e.g. www.seur.com, account.seur.com). Anything else — including look-alike typosquats, hyphenated variations, or unfamiliar TLDs like .xyz / .top / .vip — is not SEUR.
  • The domains listed above were registered within the last 7 days. New-domain age is itself a signal — SEUR has owned seur.com for years; brand-new look-alikes are almost never legitimate.
  • If you got the link from email, SMS, or social media, do not click it. Open seur.com from your browser bookmark or type the domain manually.
  • Real SEUR pages almost never ask for credentials immediately after clicking from a message — treat any such redirect as a phishing attempt until the domain is verified.