Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
groupman[.]net
“ICO Landing Page 2 - My Blog”
साक्ष्य सारांश
This domain, groupman.net, is flagged as a high-risk generic_phishing threat targeting cryptocurrency investors through an ICO-themed landing page. Analysis indicates the domain was designed to deceive users into participating in fraudulent initial coin offerings, leveraging social engineering tactics to extract sensitive information or funds. The page title, 'ICO Landing Page 2 - My Blog,' further supports this assessment, as it mimics legitimate ICO promotion sites commonly used in phishing campaigns. Infrastructure analysis reveals the domain was registered on February 21, 2026, through NameSilo, LLC, and resolves to the IP address 209.124.66.7. Security vendor detections on VirusTotal report 12 out of 95 engines flagging the domain as malicious, while it appears on four distinct security blocklists. The SSL certificate is issued by Let's Encrypt, a common choice for both legitimate and malicious sites due to its accessibility. Additional technical indicators include the use of LiteSpeed web server technology, HSTS enforcement, and HTTP/3 protocol support. The domain has been assigned a trust score of 0/100, and it is actively blocked by multiple security mechanisms, including MetaMask, SEAL, PhishDestroy, and InversionDNS. Mitigation steps for this specific threat type include immediate blocking of the domain and its associated IP (209.124.66.7) at the network perimeter. Organizations should ensure endpoint protection systems are updated to recognize the domain and its indicators of compromise. Given the ICO phishing context, user awareness training should emphasize the risks of interacting with unverified cryptocurrency investment pages, particularly those hosted on recently registered domains. Network logs should be reviewed for any prior connections to groupman.net or its IP, and affected systems should undergo forensic analysis to detect potential credential theft or unauthorized transactions. Proactive monitoring for similar domains registered through NameSilo or resolving to the same IP range is recommended to prevent follow-up attacks.
भेजे गए प्रमाण का स्नैपशॉट
- भेजा गया
- लेज़र रिकॉर्ड
- 1
- केस आईडी
PD-20260204-82BE53- PDF दस्तावेज़
- PDF प्रमाण
प्रमाण का पूरा पाठ
Section 3.1 of AUP: The domain groupman.net is being utilized for phishing activities, which constitutes a clear violation of your Acceptable Use Policy prohibiting illegal activities and fraud.
Section 5.2 of TOS: The domain is engaged in deceptive practices aimed at misleading users, which allows for immediate suspension or termination of services as outlined in your Terms of Service.
Applicable Laws (US):
Computer Fraud and Abuse Act (18 U.S.C. § 1030): This law prohibits unauthorized access to computers and the fraudulent use of information, which is applicable to phishing schemes.
Wire Fraud (18 U.S.C. § 1343): Engaging in schemes to defraud individuals via electronic communications, such as phishing, is a violation of this statute.
CAN-SPAM Act (15 U.S.C. § 7701 et seq.): This law regulates commercial email and prohibits misleading information, which is relevant to the deceptive nature of the communications associated with this domain.
Regulatory Note: Failure to take appropriate action against groupman.net may result in liability under applicable laws and could lead to regulatory scrutiny. Immediate compliance is advised to mitigate potential legal repercussions.
Data Coverage
नेटवर्क सुरक्षा इंटेलिजेंस
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 10/08/2026
पहचान समयरेखा
-
डोमेन स्थिति
पहुँच योग्य → पहुँच योग्य नहीं
-
Cloudflare Radar
Cloudflare Radar स्कैन संग्रहीत · स्कैन खोलें
-
VirusTotal
2 → 12
-
डोमेन स्थिति
पहुँच योग्य नहीं → पहुँच योग्य
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणDNS, TLS नाम और समय-मुद्राएँ
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
तकनीकें
5 उच्च-विश्वसनीयता वाली तकनीकें पहचानी गईं
वायरसटोटल विश्लेषण
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।