सुरक्षा रिपोर्ट पर जाएँ
⚠️
इस डोमेन को दुर्भावनापूर्ण के रूप में चिह्नित किया गया है।
सुरक्षा इंजन एक पहचान की रिपोर्ट कर रहे हैं: 10। अत्यधिक सावधानी बरतें - क्रेडेंशियल या व्यक्तिगत जानकारी दर्ज न करें।
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 12 days has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
12 days
Reports sent
1
Current status
HTTP 301 at latest stored check
डोमेन सुरक्षा और ख़तरे की आसूचना

pgroup[.]ro

“One moment, please...”

धमकी भरा फैसला गंभीर 96/100 साक्ष्य स्कोर
उपलब्धता अंतिम ज्ञात सक्रिय नवीनतम संग्रहीत रीचैबिलिटी अवलोकन
वायरस का कुल पता लगाना: 10/91 URLQuery threat systems: 1 alert घोटाले का प्रकार: Credential Phishing अंतिम ज्ञात सक्रिय
OTX: 1 ref 29/07/2026 1 Report Sent

संग्रहीत अवलोकन

देखा गया शीर्षक अंतर

स्कैनर को दिखाया गया शीर्षक301 Moved Permanently
आगंतुक को दिखाया गया शीर्षकOne moment, please...

साक्ष्य सारांश

आलोचनात्मक
Evidence score
96/100

The domain pgroup.ro is currently flagged as a high‑risk, active generic phishing site. Registration data shows the domain was created on October 14, 2004 and is held through ICI – Registrar. Its authoritative name servers are ns1.mxserver.ro, ns2.mxserver.ro, ns3.mxserver.ro, and ns4.mxserver.ro, all pointing to the same hosting provider. DNS resolution maps the domain to the IP address 89.44.139.129, which remains online as of the report date, July 29, 2026.

VirusTotal scans have identified two detections out of ninety‑one security vendors, indicating that at least a small subset of scanners recognize malicious characteristics associated with the domain. The domain appears on one public blocklist, specifically PhishDestroy, confirming that it has been reported and actively blocked by external threat‑intelligence feeds. No additional intelligence such as page title, SSL certificate details, or HTTP response codes is available, leaving the exact content and lure technique of the site unverified.

Analysts should treat the domain as a confirmed phishing vector based on the existing detections and blocklist entry, and incorporate it into network and endpoint filtering policies. Continuous monitoring of the IP address and name server activity is advised, as changes in hosting or infrastructure could signal further campaign development. Defenders are recommended to update threat‑intel platforms with the domain indicator, enforce URL filtering to block any access attempts, and consider broader ISP‑level blocks if similar domains emerge from the same hosting environment.

भेजे गए प्रमाण का स्नैपशॉट

भेजा गया
लेज़र रिकॉर्ड
1
केस आईडी
PD-20260729-70BA0D
कैप्चर किए गए पेज का शीर्षक
Webmail Portal Access
PDF दस्तावेज़
PDF प्रमाण
प्रमाण का पूरा पाठ
Policy Violations:
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
VirusTotal
VirusTotal
10 det.
URLQuery
यूआरएलक्वेरी
1 threat alert
OTX references
TLS प्रमाणपत्र
Let's Encrypt 29d
आयु
21.8 yr
देखी गई स्थिति
अंतिम ज्ञात सक्रिय HTTP 301
PhishDestroy
विनाश सूची
सूचीबद्ध
Reports Sent
1

Data Coverage

VirusTotal 10 / 91 यूआरएलक्वेरी 1 threat-system alert फ़िशस्टैट्स जाँच नहीं की गई ओटीएक्स 1 community reference सीएफ रडार scan completed URLScan capture संग्रहित रिपोर्ट URLScan verdict निष्कर्ष उपलब्ध नहीं डीएनएस ब्लॉक जाँच नहीं की गई TLS valid certificate, 29d कौन है 266 mo old स्क्रीनशॉट 4 captures · 3 sources चेन पुनर्निर्देशित करें जांच नहीं की गई
नेटवर्क सुरक्षा इंटेलिजेंस
Threat Detection Systems 1 alert
Detection System Indicator Verdict Alert
YARAhub by abuse.ch pgroup.ro/css/wmail.html malware Detects file containing Telegram Bot API

धमकी प्रतिक्रिया पाइपलाइन

खोज
Checks
Reports
उपलब्धता
11/12

ब्लॉकलिस्ट कवरेज

10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 10/08/2026

10 निगरानी वाले बाहरी स्रोत कोई मिलान नहीं

पहचान समयरेखा

  1. पहली दर्ज प्रविष्टि

    पहला संग्रहीत मान: पहुँच योग्य

  2. डोमेन स्थिति

    पहुँच योग्य → पहुँच योग्य नहीं

  3. डोमेन स्थिति

    पहुँच योग्य नहीं → पहुँच योग्य

सहेजा गया कैप्चर

डोमेन इंटेलिजेंस

डोमेन
सर्वर / ASN LiteSpeed · AS44043 Cyber_Folks-RO-DC_CLJ Cyber_Folks SRL, RO
IP प्रतिष्ठा IP abuse confidence 0/100 0 reports checked 29/07/2026
रजिस्ट्रार ICI - Registrar
दुरुपयोग संपर्कabuse@cyberfolks.ro
IP पता 89.44.139.129 RO
भौगोलिक स्थानRO Giurgiu, RO
नेटवर्कAS44043 · Cyber_Folks SRL
रिवर्स IPviewdns.info → rapiddns.io →
पंजीकरणनिर्मित 14/10/2004
HTTP स्थिति301 Moved Permanently
Elapsed Since First Report 1h
हम क्या मापते हैं Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: अंतिम ज्ञात सक्रिय.
प्रत्येक रिपोर्ट में क्या शामिल है संग्रहीत आउटगोइंग-रिपोर्ट रिकॉर्ड उस समय उपलब्ध साक्ष्य का संदर्भ दे सकते हैं, जैसे विक्रेता के फैसले, पंजीकरण डेटा, होस्टिंग विवरण, वर्गीकरण, या स्क्रीनशॉट। यह पृष्ठ किसी प्राप्तकर्ता द्वारा वितरित सटीक पेलोड, रसीद, पावती या कार्रवाई का अनुमान नहीं लगाता है।
तकनीकी विवरणDNS, TLS नाम और समय-मुद्राएँ
पहली बार पता चला29/07/2026
DOM Analysisanalyzed 29/07/2026DOM analysis score 0/100
Submitted URLhttp://pgroup.ro/css/wmail.html
नेमसर्वरns1.mxserver.rons2.mxserver.rons3.mxserver.rons4.mxserver.ro
MX Records0 pgroup.ro
TLS फिंगरप्रिंट
TLS अवलोकन29/05/2026 से मान्य29/07/2026 को स्कैन किया गया
TLS सब्जेक्ट वैकल्पिक नामacp-eu.rowww.acp-eu.pgroup.ro
पेज शीर्षक
One moment, please...
TLS प्रमाणपत्र
Valid transport encryption · जारीकर्ता Let's Encrypt · valid for 29 days

तकनीकें

2 उच्च-विश्वसनीयता वाली तकनीकें पहचानी गईं

Nginx OpenResty
Cloudflare Radar
इस डोमेन की रिपोर्ट करें सबूत जमा करें और दूसरों की सुरक्षा में मदद करें

वायरसटोटल विश्लेषण

10 / 91 सुरक्षा विक्रेताओं ने इस डोमेन को चिह्नित किया
View on VT
Last analyzed First positive detection Previous stored snapshot: 6 detections
alphaMountain.ai
BitDefender
Cluster25
CRDF
ईएसईटी
G-Data
Gridinsoft
SOCRadar
सोफोस
यूआरएलक्वेरी

संग्रहीत साक्ष्य

Wayback Machine Snapshot
साक्ष्य समीक्षा के लिए एक ऐतिहासिक स्नैपशॉट उपलब्ध है
View Archive
Stored Capture Evidence1 snapshot

Timestamped response metadata retained by the local collection pipeline. Each value below belongs to the displayed archive time.

Archived HTTP response HTTP 200
Requested URL: http://pgroup.ro/css/wmail.html
Final URL: https://pgroup.ro/css/wmail.html
प्रतिक्रिया
HTTP 200
HTML body
0 B
Compressed
20 B
Links
0 internal · 0 external
Selected response headers
Content-Type: text/html; charset=UTF-8
Server: LiteSpeed
HSTS: not observed DNSSEC: not observed WAF / firewall: not observed Cloaking flag: not observed
All stored response-header names (7)
ConnectionKeep-AliveContent-TypeContent-LengthDateServeralt-svc

क्या आप इस साइट से प्रभावित हुए?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।

यूरोपोल
अपने ईयू देश के लिए आधिकारिक रिपोर्टिंग चैनल ढूंढें
National police directory
रिकवरी ठगों से सावधान रहें! अपराधी जांचकर्ता, वकील या रिकवरी एजेंट होने का नाटक करते हुए पीड़ितों से दोबारा संपर्क कर सकते हैं। अग्रिम शुल्क का भुगतान न करें या क्रेडेंशियल साझा न करें। रिकवरी धोखाधड़ी के बारे में और जानें →

अपने स्थानीय अधिकारियों को रिपोर्ट करें

आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।

97-देश निर्देशिका
एआई-सहायता प्राप्त ड्राफ्ट - घटना विवरण एआई प्रदाता द्वारा संसाधित किया जाता है इसकी स्वयं समीक्षा करें और सबमिट करें

किसी भी डोमेन की जाँच करें

संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण

अभी स्कैन करें

फ़िशिंग की रिपोर्ट करें

संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें

रिपोर्ट करें

सीधा खतरा फीड

हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए

निगरानी करें

जानकारी में रहें, सुरक्षित रहें

लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।

सीधा खतरा फीड इस लिस्टिंग के खिलाफ अपील करें

बाहरी उपकरण

स्कैमएडवाइज़रScamAdviser विश्वास स्कोर 80/100स्थिति: Likely Safeस्रोत खोलें
HTML · IFRAME

इस रिपोर्ट को एम्बेड करें

इस थ्रेट इंटेलिजेंस को अपनी वेबसाइट या ब्लॉग पर साझा करें।

embed.html
<iframe
  src="https://phishdestroy.io/hi/embed/domain/pgroup.ro"
  title="PhishDestroy threat report for pgroup.ro"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>