Analysis of register.app-grvt.io shows a newly created domain (July 19, 2026) that is actively leveraged in a credential‑harvesting campaign. Google Safe Browsing has flagged the domain for social engineering, indicating it is being used to deceive users into submitting sensitive information. The domain resolves to IP address 188.114.97.3 and is hosted behind Cloudflare, as evidenced by the authoritative nameservers isabel.ns.cloudflare.com and rudy.ns.cloudflare.com. Registration was performed through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar that does not inherently provide protective reputation signals.
The domain appears on two public security blocklists and is specifically listed by PhishDestroy and ScamSniffer, reinforcing the malicious classification. VirusTotal records show the domain has been scanned by 91 vendors with no detections reported at the time of analysis; while this absence of detections does not confirm safety, it demonstrates that the threat remains primarily identified through external blocklist and Safe Browsing data. No public information is presently available regarding SSL certificate details, HTTP response codes, or page title content, leaving those vectors unverified. Defenders should immediately block traffic to 188.114.97.3 and add register.app-grvt.io to internal deny lists.
Monitoring of DNS queries for the domain and its associated Cloudflare nameservers is advised to detect potential lateral movement or additional payload delivery. Continuous re‑scanning on multi‑vendor platforms such as VirusTotal is recommended, as detection signatures may appear as the campaign evolves. Organizations should also educate users about unsolicited requests that could originate from domains similar to register.app-grvt.io, emphasizing verification of URLs before credential submission.