Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@nicenic.net.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
gro39k-cointelegraph[.]com
“Elon Musk Officially Launches GRO39K Presale”
gro39k-cointelegraph.com — अंतिम ज्ञात सक्रिय (HTTP 301). घोटाले का प्रकार: Fake Airdrop. साक्ष्य सारांश: VirusTotal 6/91 (alphaMountain.ai, Chong Lua Dao, CRDF, Fortinet, Gridinsoft); URLQuery 1 alert; Spamhaus DBL_PHISH; PhishDestroy score 82/100. रजिस्ट्रार: NiceNIC.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
On July 24 2026 analysts reviewed gro39k-cointelegraph.com following its removal from the Internet. The domain was registered on 21 February 2026 through NiceNIC International Group Co., Limited and resolves to IP 159.100.6.19, which belongs to AS214036 (Ultahost, Inc.) located in Germany. DNS is served by Cloudflare name servers shaz.ns.cloudflare.com and tadeo.ns.cloudflare.com, and the site presented a valid Let’s Encrypt certificate (R13). The web server identified LiteSpeed with HTTP/3 support, but an HTTP 500 response was recorded before the host went offline, preventing retrieval of the page body. The page title that was captured reads “Elon Musk Officially Launches GRO39K Presale”, matching a known “Token Presale” phishing kit that typically exploits interest in cryptocurrency offerings.
Threat intelligence indicates the domain appears on a single security blocklist and has been flagged by PhishDestroy. Gridinsoft assigned a trust score of 0 / 100, and six of ninety‑one VirusTotal scanners reported malicious activity, reinforcing the suspicion of phishing. No additional public sightings or reputation data are available, and the offline status limits further content analysis. Infrastructure analysis shows the use of Cloudflare for DNS and CDN, a common tactic to obscure the true origin of malicious campaigns. The German‑based IP address is consistent with other recent token‑presale phishing operations that lease short‑lived hosting.
The combination of a brand‑leveraging page title, a token‑presale kit, low trust scores, and multiple vendor detections suggests the site was deliberately crafted to lure victims into believing an affiliation with Elon Musk and the Cointelegraph brand. Defenders should continue to block the domain at network perimeters, update URL filtering lists, and monitor for any re‑registration attempts that reuse the same registrar or hosting provider.
नेटवर्क सुरक्षा इंटेलिजेंस Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | gro39k-cointelegraph.com |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-15 02:41:50 UTC
तकनीकें · 2 identified
High-performance web server compatible with Apache configurations.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
वायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of gro39k-cointelegraph.com · checked Mar 2, 2026
साक्ष्य और बाहरी रिपोर्टें
PD-20260214-891FDA Recipient: abuse@nicenic.net क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।