# gro58v-fxempire.com — SUSPICIOUS > PhishDestroy identifies gro58v-fxempire.com as a phishing site mimicking FX Empire, flagged by 0 of 95 VirusTotal vendors. Check the full report. ## Summary PhishDestroy identifies gro58v-fxempire.com as a fake FX Empire login phishing site currently under investigation. This domain was flagged by 0 of 95 VirusTotal vendors, registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on April 12, 2026. It resolves to IP 99.83.231.61 and holds a Let's Encrypt SSL certificate with no blocklist detections as of current intelligence. As this phishing domain remains active and under analysis, users should avoid interacting with it entirely. If you encounter this site, do not enter any credentials or personal information. Report the domain to your IT team or a trusted security platform for further analysis. Consider blocking the domain and IP 99.83.231.61 at your network level to prevent further exposure. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-04-12 03:05:23 - Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED - IP: 99.83.231.61 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/f081126a-1c58-47ce-b332-2a3c4f9221f5 - PhishDestroy: https://phishdestroy.io/domain/gro58v-fxempire.com/ - LLM endpoint: https://phishdestroy.io/domain/gro58v-fxempire.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/gro58v-fxempire.com/ Last updated: 2026-04-13