greentopb[.]com
Análisis de phishing y seguridad de greentopb.com
“Home - Green Top Bank”
greentopb.com — Contenido no disponible (HTTP 502). Suplantación de marca: Google; Tipo de estafa: Tech Support Scam. Resumen de las pruebas: VirusTotal 4/93 (alphaMountain.ai, CyRadar, Fortinet, Netcraft); URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 65/100.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain greentopb.com was registered on February 21 2026 and is currently taken offline. DNS resolution points to the IP address 198.12.80.250, which belongs to AS36352 operated by HostPapa and is geolocated in the United States. The site presented a page title of “Home - Green Top Bank,” but analysis indicates it was being used to impersonate Google as part of a tech support scam. The SSL certificate presented is identified as R11, confirming the presence of HTTPS encryption despite the malicious intent.
VirusTotal scans show that four of ninety‑three security vendors flagged the domain as malicious, and the domain appears on one external blocklist. PhishDestroy has already added greentopb.com to its block list, and the Gridinsoft trust score is 0 out of 100, reflecting a lack of trust. The combination of a low trust score, multiple vendor detections, and blocklist listings classifies the infrastructure as high risk. Defenders should ensure that the IP 198.12.80.250 is blocked at network perimeter, update URL filtering policies to include greentopb.com, and monitor the domain for any re‑registration or resurrection of services.
Continuous observation of the ASN and hosting provider for related activity is recommended, as HostPapa hosts other malicious campaigns. Because the site is offline, immediate mitigation focuses on preventing future resolution and ensuring that any cached content is purged from security appliances. Organizations that rely on Google services should remain vigilant for unsolicited tech‑support contacts that reference this domain, even though the domain is currently inactive.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.