ngrok[.]pro
“ERR_NGROK_3200 - The endpoint ao.signal.ngrok.pro is offline.”
संग्रहीत पहचान
क्लोकिंग चेतावनी
- क्लोकिंग प्रकार
content_split- क्लोकिंग स्कोर
- 1/6
साक्ष्य सारांश
This domain is flagged as an elevated-risk cryptocurrency wallet phishing endpoint. Analysis indicates it was designed to impersonate legitimate tunneling infrastructure, specifically targeting users of decentralized applications or wallet services. The subdomain ao.signal.ngrok.pro, referenced in the page title ERR_NGROK_3200, suggests an attempt to mimic trusted communication or signaling protocols, a common tactic in credential harvesting campaigns. Infrastructure analysis reveals the domain was registered through Gandi SAS on February 21, 2026, and resolves to the IPv6 address 2a05:d014:21b:8e01:ebba:e868:ffe7:8a42, hosted on Amazon.com, Inc. infrastructure (AS16509) in Germany. The domain appears on three security blocklists, including PhishDestroy, MetaMask, and SEAL, and is flagged by 8 out of 95 security vendors on VirusTotal. The SSL certificate is issued by Let's Encrypt (serial number E7), which, while standard for legitimate sites, is frequently exploited in phishing campaigns due to its low barrier to acquisition. The domain's current offline status (ERR_NGROK_3200) may indicate takedown or evasion efforts by the threat actor. Mitigation for this specific threat type involves several technical and procedural steps. Users should verify domain authenticity by cross-referencing with official service documentation, particularly for tunneling or wallet-related endpoints. Network-level protections should block the domain and its resolved IP address (2a05:d014:21b:8e01:ebba:e868:ffe7:8a42) at firewalls and DNS resolvers. Organizations should monitor for connections to this IP or domain in logs, as it may indicate compromised endpoints. Additionally, users who interacted with this domain should rotate credentials for any associated accounts, particularly cryptocurrency wallets, and enable multi-factor authentication where available. Security teams are advised to treat this domain as a high-confidence indicator of compromise (IOC) in threat hunting activities.
Data Coverage
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 11/08/2026
पहचान समयरेखा
-
Cloudflare Radar
Cloudflare Radar स्कैन संग्रहीत · स्कैन खोलें
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणDNS, TLS नाम और समय-मुद्राएँ
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
वायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of ngrok.pro · checked Mar 6, 2026
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।