MALICIOUS — CRITICAL
check[.]grass-fdn[.]com
4 of 91 security engines flagged the domain; the latest stored check returned HTTP 521.
- VirusTotal
- 4/91
- Blocklists
- No stored match
- Disponibilidad
- error del servidor · HTTP 521
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
check.grass-fdn.com — error del servidor (HTTP 521). Resumen de las pruebas: VirusTotal 4/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); PhishDestroy score 71/100. Registrador: Tucows.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Evidence Digest
check.grass-fdn.com is classified critical with an evidence score of 71/100. 4 of 91 security engines flagged the domain. Registered 1 Nov 2025 via Tucows Domains Inc., hosted on 172.67.206.165 (CLOUDFLARENET, US, US). The latest stored check on 9 Aug 2026 returned HTTP 521 and includes a capture.
Stored generated summary (templated)cerebras · 12/07/2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
The domain check.grass-fdn.com was registered on 2025-11-01 through Tucows Domains Inc. and is currently classified as a high‑risk generic_phishing site. An HTTP request returns status code 521, indicating the origin server is unavailable. The page title reported by scanners is “Invite Code Not Found,” which suggests the site presents a placeholder page rather than a functional service. Infrastructure analysis shows the domain resolves to IP address 172.67.206.165, which belongs to the US‑based AS13335 operated by Cloudflare, Inc. The authoritative nameservers are matt.ns.cloudflare.com and tina.ns.cloudflare.com, confirming the use of Cloudflare’s DNS and CDN services. The TLS certificate is issued by Google Trust Services under the WE1 label, providing a valid HTTPS connection. Threat intelligence sources have flagged the domain on a single security blocklist, and PhishDestroy currently lists it as blocked. VirusTotal scans indicate that 1 out of 95 security vendors has flagged the domain, reflecting limited but existing detection. The combination of a recent registration, use of a reputable CDN, and the generic_phishing classification drives the high risk rating. Observations are limited to the HTTP status, DNS configuration, and the page title; no content analysis of the landing page has been performed, leaving the exact phishing vector unknown. Defenders should consider adding check.grass-fdn.com to deny‑list rules at the network perimeter, monitor DNS queries for the domain, and, where feasible, implement sinkholing of the associated IP address. Continued observation is advised to capture any evolution in payload delivery or additional indicator expansion.
Cobertura de los datos13 recorded checks
Señales de seguridad
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Registration: grass-fdn.com
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain grass-fdn.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologías · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Evidencias archivadas
Análisis de la configuración del sitio
Datos y informes externosIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.