gro24x[.]icu
“GRO24X Official Pre-Sale — Get Up to 100% Bonus!”
gro24x.icu — असत्यापित. ब्रांड प्रतिरूपण: Genericcrypto; घोटाले का प्रकार: Fake Exchange. साक्ष्य सारांश: VirusTotal 8/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, Forcepoint ThreatSeeker); URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 74/100. रजिस्ट्रार: NiceNIC.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
PhishDestroy identifies gro24x.icu as an active generic phishing domain targeting unsuspecting users. While no specific brand or drainer kit is explicitly linked in available intelligence, the domain exhibits high-risk characteristics typical of phishing operations, including deceptive naming conventions and recent registration timelines designed to evade detection. The absence of a well-known brand association suggests opportunistic exploitation of generic trust cues to lure victims into disclosing sensitive information or executing malicious payloads. Technical analysis of gro24x.icu reveals critical indicators of compromise and fraudulent intent. The domain resolves to IP address 216.203.20.169 and is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED. Notably, VirusTotal flags this domain with a detection score of 4 out of 95 security vendors, reflecting limited but concerning recognition of its malicious nature. The domain was created on April 04, 2026, a recent registration that aligns with the operational window of opportunistic threat actors seeking to capitalize on newly established infrastructure. While Google Safe Browsing (GSB) status and blocklist participation are not specified in available data, the combination of these factors—especially the low VT score and recent creation date—demonstrates elevated risk potential. Currently, gro24x.icu remains active and poses an ongoing threat to users who may encounter it through phishing campaigns, malvertising, or typosquatting attempts. Immediate action is advised: users should avoid interacting with this domain entirely and report it to their security teams or through platforms like VirusTotal. Organizations are recommended to update firewall rules, DNS blocklists, and endpoint protection systems to include gro24x.icu and its associated IP address. Despite these measures, the domain’s recent registration and limited detection coverage suggest that some risk may persist until broader threat intelligence dissemination occurs and proactive blocking measures are universally adopted. Continuous monitoring and threat intelligence sharing remain essential to mitigate potential fallout.
नेटवर्क सुरक्षा इंटेलिजेंस Registrar context
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
SHORTDOT ज़ोन · सार्वजनिक साक्ष्य
.icu
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-17 03:02:19 UTC
वायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of gro24x.icu · checked Apr 5, 2026
साक्ष्य और बाहरी रिपोर्टें
PD-20260404-ED14C4 Recipient: abuse@nicenic.net, abuse@gen.xyz क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।