सुरक्षा रिपोर्ट पर जाएँ
⚠️
इस डोमेन को दुर्भावनापूर्ण के रूप में चिह्नित किया गया है।
सुरक्षा इंजन एक पहचान की रिपोर्ट कर रहे हैं: 6। किसी मैच की रिपोर्ट करने वाली सार्वजनिक ब्लॉक सूचियाँ: 2। अत्यधिक सावधानी बरतें - क्रेडेंशियल या व्यक्तिगत जानकारी दर्ज न करें।
डोमेन सुरक्षा और ख़तरे की आसूचना

grasslayers[.]xyz

धमकी भरा फैसला गंभीर 85/100 साक्ष्य स्कोर
उपलब्धता सर्वर त्रुटि नवीनतम संग्रहीत प्रतिक्रिया अनिर्णायक थी
वायरस का कुल पता लगाना: 6/91 Spamhaus DBL: DBL_PHISH संग्रहीत ब्लॉकलिस्ट मिलान: 2 URLQuery threat systems: 2 alerts ब्रांड प्रतिरूपण: MetaMask
19/06/2026 MetaMask 1 Report Sent CDN
रिपोर्ट सारांश

grasslayers.xyz — सर्वर त्रुटि (HTTP 502). ब्रांड प्रतिरूपण: MetaMask; घोटाले का प्रकार: Brand Impersonation. साक्ष्य सारांश: VirusTotal 6/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); URLQuery 2 alerts; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 85/100. रजिस्ट्रार: NiceNIC.

मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।

साक्ष्य सारांश
आलोचनात्मक
संदर्भ
0C7DA469
स्कोर
85/100

This domain is flagged as an elevated-risk brand impersonation threat targeting MetaMask, a widely used cryptocurrency wallet service. Analysis indicates the infrastructure was specifically designed to deceive users into believing they were interacting with the legitimate MetaMask platform, likely for the purpose of crypto asset theft or credential harvesting. The domain exhibits characteristics consistent with crypto drainer schemes, where victims are tricked into connecting wallets to malicious smart contracts, resulting in unauthorized fund transfers. Infrastructure analysis reveals grasslayers.xyz was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on May 13, 2026, and resolved to the IP address 104.21.83.153. The domain is currently offline but was previously detected by 6 out of 95 security vendors on VirusTotal, appearing on three distinct security blocklists. It has been explicitly blocked by multiple cryptocurrency security platforms, including MetaMask’s own threat intelligence systems. The creation date, while anomalous (future-dated), may indicate an attempt to evade temporal-based detection mechanisms or reflect a data entry error during registration. Mitigation steps for this specific threat type include immediate domain blacklisting across all network security layers, particularly in web filtering and DNS resolution systems. Organizations and individuals should verify wallet connection prompts against official MetaMask domains and enable transaction simulation tools to detect unauthorized smart contract interactions. End-users are advised to revoke any prior wallet connections to grasslayers.xyz via official MetaMask settings and monitor wallet activity for anomalous transactions. Given the domain’s association with crypto drainer infrastructure, affected parties should assume potential compromise of wallet permissions and consider migrating assets to new wallet addresses.

VirusTotal
VirusTotal
6 det.
URLQuery
यूआरएलक्वेरी
2 threat alerts
URLScan
यूआरएलस्कैन
TLS प्रमाणपत्र
समाप्त या असत्यापित
आयु
3 mo
देखी गई स्थिति
सर्वर त्रुटि 502
PhishDestroy
विनाश सूची
सूचीबद्ध
Reports Sent
1
डेटा कवरेज VirusTotal 6 / 91 यूआरएलक्वेरी 2 threat-system alerts फ़िशस्टैट्स जाँच नहीं की गई ओटीएक्स no community references सीएफ रडार scan completed URLScan capture संग्रहित रिपोर्ट URLScan verdict विश्लेषण पूरा हुआ डीएनएस ब्लॉक जाँच नहीं की गई TLS समाप्त या असत्यापित कौन है 3 mo old स्क्रीनशॉट 3 captures · 3 sources चेन पुनर्निर्देशित करें जांच नहीं की गई
नेटवर्क सुरक्षा इंटेलिजेंस Registrar context
Threat Detection Systems 2 alerts
Detection System Indicator Verdict Alert
Hagezi Threat Feed grasslayers.xyz malicious Sinkholed
DNS4EU grasslayers.xyz malicious Sinkholed
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation
SSL Certificate Invalid
SSL certificate is invalid or expired. Issuer:

धमकी प्रतिक्रिया पाइपलाइन

खोज
Checks
Reports
उपलब्धता
14/15
Sent Report Recorded
Stored sent-report record for registrar NICENIC INTERNATIONAL GROUP CO., LIMITED, hosting provider, 1 abuse contact
abuse@nicenic.net
19/06/2026

सार्वजनिक ब्लॉकलिस्ट स्थिति

सहेजा गया कैप्चर

TLS प्रमाणपत्र
समाप्त या असत्यापित · जारीकर्ता Let's Encrypt / E7

डोमेन इंटेलिजेंस

डोमेन
URLScan Verdict विश्लेषण पूरा हुआ score 0 report ↗
सर्वर / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden एज-आईपी प्रतिष्ठा इस डोमेन के लिए जिम्मेदार नहीं है।
रजिस्ट्रार NiceNIC RU(RU) PhishDestroy Investigation
दुरुपयोग संपर्कabuse@nicenic.net
IP पता 104.21.83.153 CDN
भौगोलिक स्थानUS San Francisco, US
नेटवर्कAS13335 · Cloudflare, Inc.
रिवर्स IPviewdns.info → rapiddns.io →
मूल आईपी सीडीएन प्रॉक्सी के पीछे छिपा हुआ है। किनारे के पते के लिए रिवर्स-आईपी परिणामों में असंबंधित किरायेदार शामिल हैं; मूल का पता लगाने के लिए निष्क्रिय DNS या प्रमाणपत्र-पारदर्शिता डेटा की आवश्यकता होती है।
पंजीकरणनिर्मित 13/05/2026 (93d) Expires 13/05/2027
HTTP स्थिति502 Error
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
पहली बार पता चला19/06/2026
DOM Analysisanalyzed 22/06/2026score 85/100
IoC Extractionscanned 01/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttps://grasslayers.xyz/
नेमसर्वरajay.ns.cloudflare.commiki.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 13/05/2026scanned 19/06/2026
Case ID
ICANN OVERSIGHT

प्रत्यायन और आरएए संदर्भ

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

मान्यता एक अनुबंध है, सुरक्षा की मुहर नहीं। ICANN शुल्क सत्यापित करें RAA §3.18 पढ़ें PHISHDESTROY INVESTIGATIONICANN funding, contracts, and DNS abuse oversight
Accountability draft कुछ भी अपने आप नहीं भेजा जाता।

Latest Classified Outcome 2026-08-14 03:06:36 UTC

Primary outcome Registration hold observed reason: Registry serverHold 95% confidence
Attribution actor class: Registry mechanism: Registry serverHold source: Rdap Status Collector
Evidence layers Availability: DNS inactive Content: Unreachable DNS: NXDOMAIN Registration: Registry serverHold
Latest HTTP observation अज्ञात Origin unreachable Http 5xx 20% 2026-08-14 02:33:13 UTC
RDAP registration Registry serverHold NICENIC INTERNATIONAL GROUP CO., LIMITED · IANA 3765 RDAP HTTP 200 source: Rdap Status Collector clientDeleteProhibitedclientTransferProhibitedserverHold expires 2027-05-13 23:59:59 UTC checked 2026-08-14 03:06:36 UTC
Observed timeline last reachable: 2026-07-02 10:19:09 UTC current episode first observed: 2026-08-05 01:45:38 UTC observed RIP window: 2026-07-02 10:19:09 UTC → 2026-08-05 01:45:38 UTC · 807.44h midpoint estimate ≈ 2026-07-19 06:02:23 UTC · precision very low · basis bounded
Availability, content, DNS and registration are independent evidence layers. NXDOMAIN, an unreachable origin or missing content alone does not prove registrar action. A registrar or provider is credited only when a direct technical marker identifies that actor. Report causality is shown separately.
इस डोमेन की रिपोर्ट करें सबूत जमा करें और दूसरों की सुरक्षा में मदद करें

वायरसटोटल विश्लेषण

6 / 91 सुरक्षा विक्रेताओं ने इस डोमेन को चिह्नित किया
View on VT
Last analyzed Previous stored snapshot: 1 detection
alphaMountain.ai
CRDF
Forcepoint ThreatSeeker
Fortinet
Gridinsoft
SOCRadar

साक्ष्य और बाहरी रिपोर्टें

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260619-A7086F Recipient: abuse@gen.xyz
Page title stored with report: Grass Airdrop - Claim Your Rewards
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 110.6 KB
Blocklist hits included with submission: MetaMask, SEAL

क्या आप इस साइट से प्रभावित हुए?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।

यूरोपोल
अपने ईयू देश के लिए आधिकारिक रिपोर्टिंग चैनल ढूंढें
National police directory
रिकवरी ठगों से सावधान रहें! अपराधी जांचकर्ता, वकील या रिकवरी एजेंट होने का नाटक करते हुए पीड़ितों से दोबारा संपर्क कर सकते हैं। अग्रिम शुल्क का भुगतान न करें या क्रेडेंशियल साझा न करें। रिकवरी धोखाधड़ी के बारे में और जानें →

अपने स्थानीय अधिकारियों को रिपोर्ट करें

आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।

97-देश निर्देशिका
एआई-सहायता प्राप्त ड्राफ्ट - घटना विवरण एआई प्रदाता द्वारा संसाधित किया जाता है इसकी स्वयं समीक्षा करें और सबमिट करें

किसी भी डोमेन की जाँच करें

संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण

अभी स्कैन करें

फ़िशिंग की रिपोर्ट करें

संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें

रिपोर्ट करें

सीधा खतरा फीड

हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए

निगरानी करें

जानकारी में रहें, सुरक्षित रहें

लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।

सीधा खतरा फीड इस लिस्टिंग के खिलाफ अपील करें
HTML · IFRAME

इस रिपोर्ट को एम्बेड करें

इस थ्रेट इंटेलिजेंस को अपनी वेबसाइट या ब्लॉग पर साझा करें।

embed.html
<iframe
  src="https://phishdestroy.io/hi/embed/domain/grasslayers.xyz"
  title="PhishDestroy threat report for grasslayers.xyz"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

एक अत्यंत सच्चा धन्यवाद-पत्र

व्यंग्यात्मक मसौदा जनरेटर

प्राप्तकर्ता
शुल्क संदर्भ

यह व्यंग्यात्मक मसौदा है। शुल्क के आंकड़े अनुमान हैं; इन्हें इस डोमेन से ठीक-ठीक जोड़ने का दावा नहीं किया जाता।