www.nse-groupe.com - suspicious URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned www.nse-groupe.com and returned a suspicious verdict (score 32), categorised as credential-harvest. The page resolved to 51.75.246.55 on OVH SAS in FR. The domain was registered 10082 days ago through Gandi SAS. 15 domains and 1 IP were contacted, over 38 HTTP requests. 1 malware sample communicates with this URL. The request followed 1 redirect before landing. This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 32) · Confidence 41%
- Scanned URL:
https://nse-groupe.com/ - Domain: www.nse-groupe.com · IP: 51.75.246.55 · AS16276 · FR
- Server: Apache
- Page title: Home - NSE Group - A world of Services
- HTTP status: 200 · text/html; charset=UTF-8
- Registrar: Gandi SAS · domain age 10082 days · created 1999-01-14
- TLS issuer: C=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication CA OV R36 · valid to Mar 1 23: · subject C=FR, ST=Allier, O=NSE, CN=*.nse-groupe.com
- Evidenced operator: NSE
- HTTP requests captured: 38
- Scan tier: fast · observed 2026-08-22 10:34:58 UTC
Redirect chain
https://nse-groupe.com/https://www.nse-groupe.com/en/
Malware communicating with this URL (1)
These samples were observed contacting or being served from www.nse-groupe.com. Each links to its full analysis.
- 51b0dabbcbea63a005a8ba5222906925f66d4e905fa889a826cc6944baa6433a - referenced ·
51b0dabbcbea63a005a8ba5222906925· first seen 2026-08-22
Antivirus & YARA (1 of 48 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- Valid TLS, no impersonation or off-origin credential post
- A signature matched text in the page (DLV_HTML_Smuggling) — pages that discuss malware can match, so this alone is not a malicious verdict
Detected technologies
- Apache
- WordPress
- Google Analytics
- jQuery
Contacted infrastructure
- 51.75.246.55 - AS16276 OVH SAS (France)
Observed indicators
- www.nse-groupe.com
- nse-groupe.com
- fonts.googleapis.com
- www.googletagmanager.com
- cdn.matomo.cloud
- sav.nse-groupe.com
- track.nse-groupe.com
- webservices.nse-groupe.com
- www.bayo.com
- sibforms.com
- 6b38f546.sibforms.com
- www.brevo.com
- fr.linkedin.com
- www.overscan.com
- www.google.com
- 51.75.246.55
- https://www.nse-groupe.com/en/
- https://www.nse-groupe.com/
- https://nse-groupe.com/wp-content/uploads/2020/10/favicon-nse.png
- https://fonts.googleapis.com/
Questions about www.nse-groupe.com
- Is www.nse-groupe.com safe?
- No. MalwareAnalyzer scanned www.nse-groupe.com on 22 Aug 2026 and returned a suspicious verdict with a score of 32 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- What malware is associated with www.nse-groupe.com?
- 1 analysed samples communicate with this URL.
- How was www.nse-groupe.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.nse-groupe.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan