Skip to security report
Domain security and threat intelligence
prochek.network favicon

prochek.network

“prochek.network”

Threat verdict Critical 95/100 evidence score
Availability Reachable · access restricted Reachable response; page content was not verified
VirusTotal detections: 5/89 Stored blocklist matches: 4 Brand impersonation: Unknown Last known active
Feb 26, 2026 Unknown
Actions API
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 5. Public blocklists reporting a match: 4. Exercise extreme caution — do not enter credentials or personal information.

Evidence Summary

CRITICAL
Score
95/100

As of July 12, 2026, the domain prochek.network has been identified as a high-risk phishing domain. This domain is flagged by 4 out of 95 security vendors on VirusTotal, indicating a moderate level of detection by the cybersecurity community. The domain is still active and resolves to the IP address 185.178.208.177, which is located in Russia (RU) and is part of the AS57724 DDOS-GUARD LTD. The SSL certificate is provided by DDOS-GUARD, a common service used to mask malicious activities. The domain was created on February 21, 2026, and is registered through PDR Ltd. d/b/a PublicDomainRegistry.com. Analysis reveals that the domain appears on five security blocklists, including those maintained by PhishDestroy, ScamSniffer, and other reputable services. The HTTP status code 503 suggests that the site may be temporarily down or under maintenance, but this does not diminish the risk it poses. Gridinsoft has assigned a trust score of 0 out of 100, signaling a high level of suspicion. Given the current status and the high risk level, defenders are advised to block this domain and monitor for any related malicious activities. The exact content of the site has not yet been analyzed, but the infrastructure and registration details strongly suggest that it is being used for phishing purposes.

VirusTotal
VirusTotal
5 det.
CF Radar
Malicious
URLScan
URLScan
TLS Certificate
ddos-guard
Age
7 mo
Observed status
Reachable · access restricted 403
PhishDestroy
DestroyList
Listed
Data coverage VirusTotal 5 / 89 OTX no community references CF Radar provider verdict: malicious URLScan capture stored report URLScan verdict Analysis completed TLS valid certificate, 551d WHOIS 7 mo old Screenshot 2 captures · 2 sources
Network Security Intelligence
CF Cloudflare Radar Verdict Malicious
Security threats Phishing Phishing

Threat Response Pipeline

Discovery
Checks
Reports
Availability
12/14

Public Blocklist Status

Evasion analysis

Cloaking & traffic-distribution check

Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.

Stored cloaking flag
Not observed
Cloaking score
0/6
Last cloaking scan

Scanner note: alive_content: raw=short_403; http=403; via=http_proxy

Live TDS fingerprint check
Seven Keitaro fingerprints plus a crawler-versus-browser comparison, run from the PhishDestroy scanner when this section scrolls into view.
Waiting

Stored Capture · 2 sources

Page Title
prochek.network
TLS Certificate
Valid transport encryption · Issued by ddos-guard · valid for 551 days

Domain Intelligence

Domain
URLScan Verdict Analysis completed score 0 report ↗
Telegram IoCs 2 extracted https://t.me/checkaml_support https://t.me/AML_GROUP
Server / ASN ddos-guard · AS57724 DDOS-GUARD DDOS-GUARD LTD, RU
IP Reputation abuse score 1/100 3 reports Port Scan checked Sep 13, 2026
IP Address 185.178.208.177 RU
GeoRU Rostov-na-Donu, RU
NetworkAS57724 · DDOS-GUARD LTD
RegistrationCreated Feb 21, 2026 (211d)
HTTP Status403 Forbidden
Technical detailsDNS, SSL SANs, timestamps
First DetectedFeb 26, 2026
DOM Analysisanalyzed Jul 9, 2026score 85/100
IoC Extractionscanned Jul 29, 20260 wallet · 2 Telegram IoCs
Nameserversdns4.regway.com
TLS Fingerprint
TLS Observationvalid from Mar 28, 2018scanned Mar 15, 2026
ICANN OVERSIGHT

Accreditation and RAA context

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Nothing is sent automatically.
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

5 / 89 security vendors flagged this domain
View on VT
Last analyzed Previous stored snapshot: 5 detections
alphaMountain.ai
Chong Lua Dao
Forcepoint ThreatSeeker
Fortinet
Gridinsoft

Community reports

Reported by 1 community member, first seen Sep 16, 2025

Stored reports
1
Unique reported URLs
1
Accepted1

Evidence & External Reports

Were You Affected by This Site?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself

Check Any Domain

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

Scan Now

Report Phishing

Submit suspicious domains to our threat database — protect the community

Report

Live Threat Feed

Recent phishing reports and observed availability changes

Monitor

Stay Informed, Stay Safe

Monitor live threats or contest this listing if you believe it's a false positive

Live Threat Feed Appeal This Listing
HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/prochek.network"
  title="PhishDestroy threat report for prochek.network"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>