# PhishDestroy threat dossier — gryzha.kz ================================================================ Fetched: 2026-07-23 19:45:18 UTC Canonical: https://phishdestroy.io/domain/gryzha.kz/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Generic Phishing ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 5/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar AlienVault OTX: 14 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 213.130.74.91 (DE, Frankfurt am Main) ASN: ASAS201993 kz-tildapublishing-1 Tilda Publishing Kaz LLC, KZ Hosting org: AS201993 Tilda Publishing Kaz LLC Registrar: ICPS Nameservers: ns1.ps.kz, ns2.ps.kz, ns3.ps.kz Registered: 2024-10-29 Page title: Избавьтесь от боли и хруста в суставах за 3−5 сеансов в Алматы по методике AManat Med без операций и уколов со скид HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E8 Expires: 2026-08-13 Status: INVALID chain Fingerprint: 036abee25bf74d15c38e112956133803729a1d0ecde6201336696e7538b35b7e Subject Alternative Names (related infrastructure — often same operator): - www.gryzha.kz ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2024-10-29 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-06-22 15:28:40 UTC (by PhishDestroy tracker) Last verified: 2026-07-23 20:20:30 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019eef84-02eb-7383-9127-5f0f72b20be6/ Wayback Machine: https://web.archive.org/web/*/gryzha.kz crt.sh CT logs: https://crt.sh/?q=%25.gryzha.kz Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=gryzha.kz AlienVault OTX: https://otx.alienvault.com/indicator/domain/gryzha.kz URLhaus: https://urlhaus.abuse.ch/host/gryzha.kz/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-12 17:36:37 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] gryzha.kz Safety Check — Medical Services Phishing Detected This domain, gryzha.kz, is currently flagged as an active phishing site targeting individuals seeking medical treatment for joint pain in Almaty. Analysis indicates the page presents itself as a legitimate service offering rapid relief through a method called 'AManat Med,' with promotional discounts on diagnostic procedures. The domain was registered on October 29, 2024, and remains operational as of July 12, 2026, resolving to the IP address 213.130.74.91. Infrastructure analysis reveals the use of a Let's Encrypt SSL certificate, which provides basic encryption but does not validate the legitimacy of the site's content or operators. The domain appears on two security blocklists, including PhishDestroy and BLP-Malware, and has been documented in 14 threat intelligence pulses within AlienVault OTX. Additionally, five out of 95 security vendors on VirusTotal have flagged gryzha.kz as malicious, further corroborating its classification as a high-risk phishing site. The presence of tracking technologies such as Google Tag Manager, Google Analytics, and Facebook Pixel suggests an attempt to monitor user interactions, which is consistent with fraudulent schemes designed to optimize conversion rates or harvest personal data. What remains uncertain is the exact nature of the data being collected or the ultimate objective of the operators. The site may be designed to solicit payments for non-existent services, capture sensitive personal or financial information, or distribute malware under the guise of medical consultations. The use of Tilda, a website builder platform, indicates a low-effort deployment, which is typical of opportunistic phishing campaigns. Defenders should treat this domain as compromised and implement blocking measures at the network and endpoint levels. Organizations are advised to monitor for any indicators of compromise associated with this IP or domain, particularly in regions where Russian-language phishing campaigns are prevalent. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 539cb98730871486358e58b899ac739e TLS cert SHA-256: 036abee25bf74d15c38e112956133803729a1d0ecde6201336696e7538b35b7e ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/gryzha.kz/ JSON API: https://api.destroy.tools/v1/check?domain=gryzha.kz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 188,947 domains (58,596 alive under monitoring, 128,729 confirmed takedowns/dead). Site: https://phishdestroy.io