geteegztd[.]store
“Маркет - Getgems”
geteegztd.store — सामग्री अनुपलब्ध. ब्रांड प्रतिरूपण: Telegram; घोटाले का प्रकार: Brand Impersonation. साक्ष्य सारांश: VirusTotal 2/93 (SOCRadar); PhishDestroy score 56/100. रजिस्ट्रार: REGRU-RU.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
On 21 February 2026 the domain geteegztd.store was registered through the REGRU‑RU registrar and assigned the Russian name servers ns1.reg.ru and ns2.reg.ru. The domain resolves to the IPv4 address 31.57.34.181, which is announced by AS207994 (Blockchain Creek B.V.) and geolocated to the Netherlands. No TLS certificate is presented; the web service responded over HTTP/3 without encryption, which is atypical for credential‑stealing sites that usually employ HTTPS to gain user trust. The only visible page element captured is the title “Маркет – Getgems”, which does not reference the targeted brand. Nevertheless, the intelligence set classifies the campaign as a brand‑impersonation attempt against Telegram, indicating that the operator likely intends to lure Telegram users to a counterfeit service.
VirusTotal analysis recorded 2 detections out of 93 scanned security vendors, confirming that at least a minority of scanners flagged the domain as malicious. Independent reputation services assign a Gridinsoft trust score of 0 / 100 and list the domain on a single public blocklist. PhishDestroy has already taken the domain offline and added it to its blocklist, reducing immediate exposure but not guaranteeing that the infrastructure will not be reused. The limited evidence leaves several aspects uncertain: the exact phishing kit, the presence of credential‑capture forms, and any additional hosting infrastructure beyond the single IP are not publicly disclosed.
Defenders should therefore treat the domain as a confirmed malicious indicator. Recommended actions include adding geteegztd.store and its resolving IP 31.57.34.181 to network‑level deny lists, monitoring the registrar REGRU‑RU for new registrations that reuse the same name‑server pattern, and updating URL‑filtering rules to block any future resolution to the same host.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
तकनीकें · 1 identified
HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% विश्वासवायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साक्ष्य और बाहरी रिपोर्टें
PD-20260206-C7B047 Recipient: abuse@reg.ru क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।